Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Single Sign-on Problem

Status
Not open for further replies.
Jun 25, 2003
2,949
US
I got this email, but I have never dealt with Single Sign-on so I am posting it for others to chew on. Thanks. - Marv

Problem: After putting on NWclient v.4.9 onto XP Pro machine, password authentication fails with NT servers in either workgroup or domain access to shared directories.

To recreate this problem.
1. Have a Novell server that is not running "single sign on"
2. Have a user enable "single sign on" on their desktop/client
3. reboot, logon and remove "single sign on"

Regardless of your NT authentication, you now have no more access then that of a guest.

Un-installing the nwclient, and only having MS authentication works fine. Install the nwclient and your authentication will fail.

Have tried changing network provider order, binding order - no effect. Have also uninstalled v4.9 and installed v4.83sp2 client. Also deleting hkey_local machine\software\novell registry.

We are planning on implementing single sign on, so in testing what if... I crippled my machine. I'm not sure what I should be looking at or how to phrase a correct question since no actual errors are appearing.


Marvin Huffaker MCNE, CNE
Marvin Huffaker Consulting
 
Single Sign-on was a pain in the rump and Novell broke it with eDir85, so they developed NMAS. This TID doesn't address your issue directly, but it may shed some light on this issue your customer is having.


If your customers intent is only to sync passwords between a tree and a domain, then stear them towards DirXML. Pretty easy to install and will do the user ID info and passwords. One word of caution is even if you choose one way sync fron NDS to AD/Domain, if you delete the user in Windows, it will get deleted in NDS, and if you rename the login ID in Windows, the CN name will get changed in NDS. Just one of those snafoos, o and then there is the issue with using a template to create users, the NDS atribute OtherName get apended to the Windows user ID. Got stylesheets to correct all those snafoos, plus just got a really kewl one that will sync users from NDS to AD/Domain based on thier group memebership, cause not everyone is jumping on the Winblows bandwagon, some people just have specific needs. :)

=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
Brent Schmidt Certified nut case [hippy]
Senior Network Engineer
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top