Password Sync Search Scope

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi,

I have a user directory structure in AD that mimics a typical org chart 
such that my ou=People directory contains additional ou's as subtrees 
that represent different departments.  I have a windows sync agreement 
in FDS set up, and after manually adding the various ou's on the FDS 
side, all the users sync over properly in all the subtrees.

My problem is with the password sync service for windows.  Upon changing 
a user's password that has already been replicated to FDS from AD, I see 
in the access logs a search along these lines:

SRCH base="ou=People,dc=my,dc=domain" scope=1 
filter="(ntUserDomainId=myUser)" attrs=ALL

with the result indicating no entries found:

RESULT err=0 tag=101 nentries=0 etime=0

The myUser account is at ou=MyDept,ou=People,dc=my,dc=domain, but the 
password sync service issues a search request to only search the 
ou=People directory non-recursively (i.e. scope=1).  I don't see any 
options in either the PassSync.msi setup or in the registry keys to 
force the service to do a scope=2 recursive search.  I tried to use the 
syntax "ou=People,dc=my,dc=domain?sub", but it doesn't seem to recognize 
that either.  Is there any workaround for this besides to synchronize 
all of my users to a single directory on FDS?

Thanks,
Brian




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux