Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Tuesday, September 11, 2012

TIPS & TRICKS: Active Directory Users & Computers Filtering

Handy little LDAP query to filter users who have not changed passwords after a certain date (in this case, September 5th) (all one line):


(&(objectCategory=user)(pwdLastSet>=129913020000000000)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))


Here are the steps to run the filter:


  • In ADUC, click on Set Filtering options icon
  • click "Create custom", then Customize button
  • click on Advanced tab, then enter (or copy/paste) LDAP query:
    • (&(objectCategory=user)(pwdLastSet>=129913020000000000)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))
  • then click OK button, then OK again to close Filter Options
  • In OU list at left, navigate to your OU, which will now show only users who have changed password since cutoff time.
  • 129913020000000000 = number of 100 nanosecond intervals since Jan 1, 1601 to 9/5/2012 12:00 AM.
  • (!(userAccountControl:1.2.840.113556.1.4.803:=2)) is a bitwise operation to exclude disabled users.
  • If you want to return to seeing all users and objects, you need to clear the filter, by clicking on Set Filtering options icon, then click "Show all types of objects"
  • You can reverse the query to see users who haven't changed password yet, by changing the query string >= to <=




Tuesday, January 12, 2010

TIPS & TRICKS: Connecting to OS X Share from Windows 7

For some reason, I had not yet tried an AFP connection to an OS X server share from Windows 7 yet. So, I tried it today. Opened Computer, clicked on Map network drive and proceeded to map the drive. After providing the correct credentials, Windows 7 would not connect.

What do I do next? Search for an answer online (okay, I googled it). It took me a couple tries, but I finally found the following answer. Go to Administrative Tools > Local Security Policy > Local Policies - Security Options. Find the policy that's called:

Network security: LAN Manager authentication level

Then modify the setting to show Send LM & NTLM responses. Next, in the same location, find the policy that's called:

Network security: Minimum session security for NTLM SSP

Then modify the setting to disable Require 128-bit encryption. In my attempt, I only modified the first setting and was able to get in. The second setting was listed in the answer I found here:

http://www.tomshardware.com/forum/75-63-windows-samba-issue

Basically, regardless of the type of connection (i.e. Samba, AFP, etc.) Windows needs to be able to send the correct type of challenge/response authentication protocol. By default, Windows 7 is not allowed to send the right one/type to OS X. This change in the local policies worked for me.

Happy Computing.

Sunday, October 05, 2008

TIPS & TRICKS: Windows Save Usernames/Passwords

For some network connections and resources, Windows has the ability to save the username and password (domain too) to allow access without having to input credentials each time.

However, I've always been a proponent of not having the machine remember passwords for security reasons. This is how to remove it:

1. Click Start and select Run
2. In the Open field type "rundll32.exe keymgr.dll, KRShowKeyMgr"
3. Once the Stored Usernames and Passwords interface opens you can select any of the entries and select Properties to view the existing information
4. To remove a saved password you can select one of the entries and select Remove. A confirmation screen will appear. Click on OK and the account will be removed
5. You can add additional saved passwords as well by clicking on the Add button and entering the appropriate information
6. Repeat the steps above as needed to add, remove or edit saved passwords
7. When you are done using the interface click the Close button


I've tested this with Windows XP and Vista. Hope that helps.