Koozali.org: home of the SME Server

NT4 PDC <> SME user and password syn

Andre Courchesne

NT4 PDC <> SME user and password syn
« on: August 27, 2003, 09:54:11 PM »
Hi,

  Is there an easy way to sync an NT4 PDC user and password database with a
SME server acting as a gateway?

  I'm trying to implement proxy authentification, but I do not want user to
have to enter a separate username and password in Internet explorer (it is
hard enough for them to remember their domain password to log-on each
morning...).

  IE allows you to use your current session username and password to
authenticate to the proxy and this works great if I have an account on the
proxy server that has the same username and password as on the PDC.

  But if a user changes his PDC password, he will be out of sync on the
password for the proxy authentification...

  Any ideas, links,...

Shane

Re: NT4 PDC <> SME user and password syn
« Reply #1 on: August 29, 2003, 06:06:04 AM »
I'm going to devote a couple of hours to this one next week hopefully.
There is a link to get you started.

http://www.mail-archive.com/devinfo@lists.e-smith.org/msg01146.html

Let us know how you go

Shane

Andre Courchesne

Re: NT4 PDC <> SME user and password syn
« Reply #2 on: August 29, 2003, 05:43:32 PM »
I have given-up on it for now.

My main use was for proxy authentication. I wanted to avoid the user to re-enter his username and password when starting internet explorer and at the same time have the username in the DansGuardian log.

I have found an other way using IdentD which DansGuardian supports. Unfortunatly the hardest part was the Windows workstation which do not have a IdentD server by default.

I found the last part to and now it is all transparent to the user except when he accesses a banned page. And when this happens his login name shows up in my DansGuardian log...

I'll probably write an how-to on this with all the tools later.

shane

Re: NT4 PDC <> SME user and password syn
« Reply #3 on: August 30, 2003, 08:55:57 AM »
Glad you got it sorted...
I will let you know if I have any luck with the authentication via samba as this would appear to be the best alternative for a single client login for all SME delivered services.