Group membership updates in LDAP
 




IT Certification FAQ

 
|
Home
|
Microsoft
|
CISCO
|
CompTIA
|
Exam/Study FAQ
|
Employment FAQ
| Links  | Forums  |
Book Reviews


FAQFAQ  SearchSearch  MemberlistMemberlist  UsergroupsUsergroups  RegisterRegister  ProfileProfile  Log in to check your private messagesPrivate messages  Log inLog in

Group membership updates in LDAP

 
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.active_directory
Author Message
adiavr@gmail.com
Guest





PostPosted: Fri Aug 31, 2007 12:29 am    Post subject: Group membership updates in LDAP Reply with quote

We have several DC's in our organization in multiple sites. In one
site, we use an application that authenticates users based on their
group membership, using LDAP (e.g. checking if johndoe is part of the
Developers group).

When adding or removing an user from the group, there is a significant
delay before the updated group membership is shown in the LDAP
directory of this site's DC. I've used the Softerra LDAP Browser to
check group membership and it takes more than 30 mins before the
updated member list is replicated. Password changes are almost instant
though.

I've had to point the LDAP server setting in our application to the
Operations Master DC which is in a different site as a workaround.
However I would like to have it point to local DC for performance and
reliability.

Why does group membership take so long to propagate in LDAP?
Back to top
adiavr@gmail.com
Guest





PostPosted: Fri Aug 31, 2007 12:29 am    Post subject: Re: Group membership updates in LDAP Reply with quote

The DC in our site is linked with both DC's from the primary site. One
of them is a GC for that site and the other one operations master.

On Aug 30, 2:53 pm, "Mathieu CHATEAU" <gollum...@free.fr> wrote:
Quote:
Hello,

DC replication occurs every 10 minutes per default.
What is your replication topology ?
Is your operation master fsmo role not on a global catalog ? (it wouldn't)

--
Cordialement,
Mathieu CHATEAUhttp://lordoftheping.blogspot.com

adi...@gmail.com> wrote in message

news:1188510623.291592.317910@r23g2000prd.googlegroups.com...

We have several DC's in our organization in multiple sites. In one
site, we use an application that authenticates users based on their
group membership, using LDAP (e.g. checking if johndoe is part of the
Developers group).

When adding or removing an user from the group, there is a significant
delay before the updated group membership is shown in the LDAP
directory of this site's DC. I've used the Softerra LDAP Browser to
check group membership and it takes more than 30 mins before the
updated member list is replicated. Password changes are almost instant
though.

I've had to point the LDAP server setting in our application to the
Operations Master DC which is in a different site as a workaround.
However I would like to have it point to local DC for performance and
reliability.

Why does group membership take so long to propagate in LDAP?
Back to top
Mathieu CHATEAU
Guest





PostPosted: Fri Aug 31, 2007 12:29 am    Post subject: Re: Group membership updates in LDAP Reply with quote

Hello,

DC replication occurs every 10 minutes per default.
What is your replication topology ?
Is your operation master fsmo role not on a global catalog ? (it wouldn't)

--
Cordialement,
Mathieu CHATEAU
http://lordoftheping.blogspot.com


<adiavr@gmail.com> wrote in message
news:1188510623.291592.317910@r23g2000prd.googlegroups.com...
Quote:
We have several DC's in our organization in multiple sites. In one
site, we use an application that authenticates users based on their
group membership, using LDAP (e.g. checking if johndoe is part of the
Developers group).

When adding or removing an user from the group, there is a significant
delay before the updated group membership is shown in the LDAP
directory of this site's DC. I've used the Softerra LDAP Browser to
check group membership and it takes more than 30 mins before the
updated member list is replicated. Password changes are almost instant
though.

I've had to point the LDAP server setting in our application to the
Operations Master DC which is in a different site as a workaround.
However I would like to have it point to local DC for performance and
reliability.

Why does group membership take so long to propagate in LDAP?
Back to top
Display posts from previous:   
Post new topic   Reply to topic    Forum Index -> microsoft.public.windows.server.active_directory All times are GMT
Page 1 of 1

 

Copyright © 2002-2006 Web-S-Sense Pty. Ltd. All rights reserved.

Powered by phpBB
Advertising | Policies/Disclaimers | Contact us | Link to us


Featured Sites: Free Antivirus and Antispyware Info | Free PC Support | MCSE Directory