Re: Windows2000 user verification

To answer your first question:

>From my understanding of Active Directory and Windows 2000's design, neither
openLDAP (nor any other LDAP server that is *NOT* Active Directory) will
work to authenticate users to Active Directory, although (with some work)
Active Directory can authenticate users to other systems that use an LDAP
directory as their userid database.  There are several reasons for this, the
primary one being that MS keeps the account's SID (Security ID) as an
attribute, and this is NOT made available  to store into other directory
services.  BTW, this is the same reason that while the Windows 2000 KDC can
serve Kerberos tickets to other consumers, Windows 2000 can not use tickets
served by other KDCs.

Another problem is that in order to login to a Windows 2000 forest, you must
have a Global Catalog available - something that non-AD directory services
don't provide.

Also, beware - I just found out at a Burton Group briefing yesterday that
Active Directory does not implement the inetOrgPerson object class - so even
using AD with some directory-enabled apps (those that expect inetOrgPerson
to be the base object class) may be iffy.  Needless to say, now I am going
to have to reconcile the schemas, and see what the differences really are.

Since it does not appear to be possible to do what you want, the other
questions, unfortunately, are a moot point at this time.  Sorry 'bout that.

