IT Help

Thread Tools
 
Search this Thread
 
Old Dec 1, 2006 | 01:35 PM
  #1  
motopsyko32's Avatar
Thread Starter
I Love To Post!
 
Joined: Jan 2003
Posts: 6,753
From: Miami, FL
motopsyko32 will become famous soon enough
IT Help

How do you avoid the use of GENERIC ID's on your network but still run applications that require access to certain shares that are locked down by an AD group?

If you need me to explain in more detail, just ask...
Old Dec 1, 2006 | 03:05 PM
  #2  
Suicidl's Avatar
WWW.Sickinnovations.com
 
Joined: May 2004
Posts: 18,216
From: Usa
Suicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to behold
Re: IT Help

WTF
Old Dec 1, 2006 | 04:17 PM
  #3  
Hazen's Avatar
Registered User
 
Joined: Oct 2002
Posts: 7,852
From: O-town FL
Hazen is a decent person
Re: IT Help

Wiiiiieeeeeerrrrddooooooooooo.

Where is Scott3479132467835568 when you need him?
Old Dec 1, 2006 | 04:54 PM
  #4  
motopsyko32's Avatar
Thread Starter
I Love To Post!
 
Joined: Jan 2003
Posts: 6,753
From: Miami, FL
motopsyko32 will become famous soon enough
Re: IT Help

yeah isnt he a nerd IT guy?
Old Dec 1, 2006 | 04:55 PM
  #5  
motopsyko32's Avatar
Thread Starter
I Love To Post!
 
Joined: Jan 2003
Posts: 6,753
From: Miami, FL
motopsyko32 will become famous soon enough
Re: IT Help

some more background. App runs on a Domino Server and needs to access a txt file on a Windows Share that is locked down through AD. We want to let the Domino script access this info without haveing to create a generic id that can be compromised and untraced.
Old Dec 1, 2006 | 05:05 PM
  #6  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

Ok I'm here and reading ....

Is the share on a domain controller?
Old Dec 1, 2006 | 05:07 PM
  #7  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

and is it server 2k3?
Old Dec 1, 2006 | 05:10 PM
  #8  
crtchrktrcr's Avatar
B.T.M.
 
Joined: Feb 2004
Posts: 17,252
crtchrktrcr is a splendid one to beholdcrtchrktrcr is a splendid one to beholdcrtchrktrcr is a splendid one to beholdcrtchrktrcr is a splendid one to beholdcrtchrktrcr is a splendid one to beholdcrtchrktrcr is a splendid one to beholdcrtchrktrcr is a splendid one to behold
Re: IT Help

moto, here's the deal, scoot will fix all your IT issues, if you come fix his roof.
Old Dec 1, 2006 | 05:11 PM
  #9  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

are you trying to do something with migrating from lotus notes to exchange?
give me the full rundown
Old Dec 1, 2006 | 05:15 PM
  #10  
motopsyko32's Avatar
Thread Starter
I Love To Post!
 
Joined: Jan 2003
Posts: 6,753
From: Miami, FL
motopsyko32 will become famous soon enough
Re: IT Help

its not a DC
it is win2k3

We are trying to automate the creation/deletion/changes in Notes accounts...

The Domino server runs a script that access the x: and y: drives which are 2 shares in a win2k3 server. These shares are locked under the OU "Restricted".

There are various other shares in the same OU.

The Domino app has to map these drives and import the txt file which contains personnell info.

If the Generic ID is compromised, they will have access to Personnell data and other restricted ****
Old Dec 1, 2006 | 05:18 PM
  #11  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

oj that helps .... let me think about this for a minute
Old Dec 1, 2006 | 05:22 PM
  #12  
motopsyko32's Avatar
Thread Starter
I Love To Post!
 
Joined: Jan 2003
Posts: 6,753
From: Miami, FL
motopsyko32 will become famous soon enough
Re: IT Help

thanks
Old Dec 1, 2006 | 06:07 PM
  #13  
Suicidl's Avatar
WWW.Sickinnovations.com
 
Joined: May 2004
Posts: 18,216
From: Usa
Suicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to beholdSuicidl is a splendid one to behold
Re: IT Help

wow

scott3824596845236578
when you get to florida can you fix my computer
Old Dec 1, 2006 | 06:07 PM
  #14  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

Can you set up a service account in AD to access the shares?
Old Dec 1, 2006 | 06:08 PM
  #15  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

Originally Posted by suicidl
wow

scott3824596845236578
when you get to florida can you fix my computer
Of course buddy
Old Dec 1, 2006 | 06:12 PM
  #16  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

Originally Posted by scott3824
Can you set up a service account in AD to access the shares?
Heres what I'm getting at ....

Service Accounts are geared to allow software applications to make use of network services. The passwords for these accounts should be changed through the Domino app user interface (not through the Active Directory Users and Computers MMC snap-in) on a regular basis, since they are normally granted advanced privileges. To remove security vulnerability configure Group Policy settings to deny the account interactive logon rights. To add security use only one security account per application - like if you have a similar instance for a different app or different share create a different service account for that.
Old Dec 1, 2006 | 06:13 PM
  #17  
3824's Avatar
I Chose to No Longer Post
 
Joined: Apr 2004
Posts: 37,827
3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future3824 has a brilliant future
Re: IT Help

That is more secure than just granting a generic user rights. If you don't think it will work let me know I'll figure something else out to help you.
Old Dec 1, 2006 | 06:19 PM
  #18  
motopsyko32's Avatar
Thread Starter
I Love To Post!
 
Joined: Jan 2003
Posts: 6,753
From: Miami, FL
motopsyko32 will become famous soon enough
Re: IT Help

Originally Posted by scott3824
Heres what I'm getting at ....

Service Accounts are geared to allow software applications to make use of network services. The passwords for these accounts should be changed through the Domino app user interface (not through the Active Directory Users and Computers MMC snap-in) on a regular basis, since they are normally granted advanced privileges. To remove security vulnerability configure Group Policy settings to deny the account interactive logon rights. To add security use only one security account per application - like if you have a similar instance for a different app or different share create a different service account for that.
the process will be handled by a Domino script not manually so the changing the password will be a no-no...

Basically what the bossman wants is a way to access these shares with system services without opening the share to EVERYONE for access and without creating Generic Id's...

Only thing I have comeup with so far is to add the generic ID to an OU that will not allow local login so if compromised, they cannmot gain access to our network through login, but that is not the goal. The goal would be to limit or stop the use of generic ID's (I dont think its possible, but I also know I dont know it all )


BTW, Domino does not tie into AD accounts either.




All times are GMT -4. The time now is 05:26 PM.