Actually, I'm more concerned with what OU the collaborator accounts will live in, and whether we'll have ou admin rights on them. Specifically, will we be able to administer these accounts the same way we can our regular accounts? Tami Martin <[email protected]> wrote:
Ti/Karl,
Collaborator account password resets are done by the help desk through a tool that is not distributed by division. There is an account profile tool at mypassword.anl.gov that can be used by the collaborator to reset passwords if they have a profile defined. cc'd Rich for input.
Thanks, Tami
On 3/28/13 4:08 PM, Schmidt, Karl E. wrote:
Sorry, Ti. (and thank you for the ping)
I am still looking into the LDAP attributes.
If those are available, #2 and #2 shouldn't be an issue...I do not know the business rules around #1. Tami, do you know where password resets are done?
-Karl
-----Original Message----- From: Ti Leggett [mailto:[email protected]] Sent: Thursday, March 28, 2013 9:24 AM To: Schmidt, Karl E. Cc: [email protected] Admins; Martin, Tamara L.; Lehman, David S. Subject: Re: LDAP Attributes
*ping*
On Mar 21, 2013, at 9:49 AM, Ti Leggett <[email protected]> wrote:
3 things that we just thought of.
1) Would we have the ability to do password resets for MCS collaborator accounts? 2) Can we get a test OU that we can use to test migrating our current data in to test out how this will work and how we will start using this for all of our services 3) Can we get a test collaborator OU that we can use to test converting from a collaborator to regular and vice versa and how that will affect our services
On Feb 26, 2013, at 8:37 AM, Ti Leggett <[email protected]> wrote:
And here's a snapshot of our current hierarchy:
<Screen Shot 2013-02-26 at 8.36.48 AM.png>
On Feb 26, 2013, at 8:35 AM, Ti Leggett <[email protected]> wrote:
Here's the list of all the object classes and attributes we use. Obviously the Samba ones could probably be replaced with MS AD specific ones.
Object Classes: account automount automountMap dcObject inetOrgPerson ldapPublicKey nisNetgroup organizationalRole organizationalUnit person posixAccount posixGroup sambaDomain sambaSamAccount sambaUnixIdPool simpleSecurityObject top uidObject
Attributes: automountInformation cn dc description displayName dn employeeType gidNumber givenName homeDirectory homePhone homePostalAddress loginShell mail memberUid nisNetgroupTriple objectClass ou roomNumber sambaAcctFlags sambaDomainName sambaForceLogoff sambaKickoffTime sambaLockoutDuration sambaLockoutObservationWindow sambaLockoutThreshold sambaLogoffTime sambaLogonTime sambaLogonToChgPwd sambaMaxPwdAge sambaMinPwdAge sambaMinPwdLength sambaNextRid sambaNTPassword sambaPrimaryGroupSID sambaPwdCanChange sambaPwdHistoryLength sambaPwdLastSet sambaPwdMustChange sambaSID sn sshPublicKey telephoneNumber uid uidNumber
-- Tami Martin 630-252-7372 IT Service Automation Manager Computer and Information Systems Division Argonne National Laboratory
ITSA: Providing Effective and Efficient IT Management Solutions
-- Craig