1

Topic: Integrate Microsoft AD for user authentication and address Book

==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): 1.6.2
- Deployed with iRedMail Easy or the downloadable installer? download installer
- Linux/BSD distribution name and version:  Rocky Linux 8
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? no
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====

I am trying to integrate Microsoft Active Directory for user authentication and address book from following URL: docs.iredmail.org/active.directory.html
when i run blow mention command
postmap -q user@example.com ldap:/etc/postfix/ad_virtual_mailbox_maps.cf and enable debug level 1 and when disable debug level on 0 then i did not see as per document.

postmap: dict_ldap_debug: ldap_create
postmap: dict_ldap_debug: ldap_url_parse_ext(ldap://ad.example.com:389)
postmap: dict_ldap_debug: ldap_sasl_bind
postmap: dict_ldap_debug: ldap_send_initial_request
postmap: dict_ldap_debug: ldap_new_connection 1 1 0
postmap: dict_ldap_debug: ldap_int_open_connection
postmap: dict_ldap_debug: ldap_connect_to_host: TCP ad.example.com:389
postmap: dict_ldap_debug: ldap_new_socket: 6
postmap: dict_ldap_debug: ldap_prepare_socket: 6
postmap: dict_ldap_debug: ldap_connect_to_host: Trying 10.60.0.10:389
postmap: dict_ldap_debug: ldap_pvt_connect: fd: 6 tm: 10 async: 0
postmap: dict_ldap_debug: ldap_ndelay_on: 6
postmap: dict_ldap_debug: attempting to connect:
postmap: dict_ldap_debug: connect errno: 115
postmap: dict_ldap_debug: ldap_int_poll: fd: 6 tm: 10
postmap: dict_ldap_debug: ldap_is_sock_ready: 6
postmap: dict_ldap_debug: ldap_ndelay_off: 6
postmap: dict_ldap_debug: ldap_pvt_connect: 0
postmap: dict_ldap_debug: ldap_open_defconn: successful
postmap: dict_ldap_debug: ldap_send_server_request
postmap: dict_ldap_debug: ber_scanf fmt ({it) ber:
postmap: dict_ldap_debug: ber_scanf fmt ({i) ber:
postmap: dict_ldap_debug: ber_flush2: 27 bytes to sd 6
postmap: dict_ldap_debug: ldap_result ld 0x55c861dd4b30 msgid 1
postmap: dict_ldap_debug: wait4msg ld 0x55c861dd4b30 msgid 1 (timeout 10000000 usec)
postmap: dict_ldap_debug: wait4msg continue ld 0x55c861dd4b30 msgid 1 all 1
postmap: dict_ldap_debug: ** ld 0x55c861dd4b30 Connections:
postmap: dict_ldap_debug: * host: ad.mashospital.org  port: 389  (default)
postmap: dict_ldap_debug:   refcnt: 2  status: Connected
postmap: dict_ldap_debug:   last used: Thu Mar 23 15:30:28 2023
postmap: dict_ldap_debug:
postmap: dict_ldap_debug: ** ld 0x55c861dd4b30 Outstanding Requests:
postmap: dict_ldap_debug:  * msgid 1,  origid 1, status InProgress
postmap: dict_ldap_debug:    outstanding referrals 0, parent count 0
postmap: dict_ldap_debug:   ld 0x55c861dd4b30 request count 1 (abandoned 0)
postmap: dict_ldap_debug: ** ld 0x55c861dd4b30 Response Queue:
postmap: dict_ldap_debug:    Empty
postmap: dict_ldap_debug:   ld 0x55c861dd4b30 response count 0
postmap: dict_ldap_debug: ldap_chkResponseList ld 0x55c861dd4b30 msgid 1 all 1
postmap: dict_ldap_debug: ldap_chkResponseList returns ld 0x55c861dd4b30 NULL
postmap: dict_ldap_debug: ldap_int_select
postmap: dict_ldap_debug: read1msg: ld 0x55c861dd4b30 msgid 1 all 1
postmap: dict_ldap_debug: ber_get_next
postmap: dict_ldap_debug: ber_get_next: tag 0x30 len 16 contents:
postmap: dict_ldap_debug: read1msg: ld 0x55c861dd4b30 msgid 1 message type bind
postmap: dict_ldap_debug: ber_scanf fmt ({eAA) ber:
postmap: dict_ldap_debug: read1msg: ld 0x55c861dd4b30 0 new referrals
postmap: dict_ldap_debug: read1msg:  mark request completed, ld 0x55c861dd4b30 msgid 1
postmap: dict_ldap_debug: request done: ld 0x55c861dd4b30 msgid 1
postmap: dict_ldap_debug: res_errno: 0, res_error: <>, res_matched: <>
postmap: dict_ldap_debug: ldap_free_request (origid 1, msgid 1)
postmap: dict_ldap_debug: ldap_parse_result
postmap: dict_ldap_debug: ber_scanf fmt ({iAA) ber:
postmap: dict_ldap_debug: ber_scanf fmt (}) ber:
postmap: dict_ldap_debug: ldap_msgfree
postmap: dict_ldap_debug: ldap_search_ext
postmap: dict_ldap_debug: put_filter: "(&(objectclass=person)(userPrincipalName=md@mashospital.org))"
postmap: dict_ldap_debug: put_filter: AND
postmap: dict_ldap_debug: put_filter_list "(objectclass=person)(userPrincipalName=md@mashospital.org)"
postmap: dict_ldap_debug: put_filter: "(objectclass=person)"
postmap: dict_ldap_debug: put_filter: simple
postmap: dict_ldap_debug: put_simple_filter: "objectclass=person"
postmap: dict_ldap_debug: put_filter: "(userPrincipalName=md@example.com)"
postmap: dict_ldap_debug: put_filter: simple
postmap: dict_ldap_debug: put_simple_filter: "userPrincipalName=md@example.com"
postmap: dict_ldap_debug: ldap_send_initial_request
postmap: dict_ldap_debug: ldap_send_server_request
postmap: dict_ldap_debug: ber_scanf fmt ({it) ber:
postmap: dict_ldap_debug: ber_scanf fmt ({) ber:
postmap: dict_ldap_debug: ber_flush2: 143 bytes to sd 6
postmap: dict_ldap_debug: ldap_result ld 0x55c861dd4b30 msgid 2
postmap: dict_ldap_debug: wait4msg ld 0x55c861dd4b30 msgid 2 (timeout 10000000 usec)
postmap: dict_ldap_debug: wait4msg continue ld 0x55c861dd4b30 msgid 2 all 1
postmap: dict_ldap_debug: ** ld 0x55c861dd4b30 Connections:
postmap: dict_ldap_debug: * host: ad.mashospital.org  port: 389  (default)
postmap: dict_ldap_debug:   refcnt: 2  status: Connected
postmap: dict_ldap_debug:   last used: Thu Mar 23 15:30:28 2023
postmap: dict_ldap_debug:
postmap: dict_ldap_debug: ** ld 0x55c861dd4b30 Outstanding Requests:
postmap: dict_ldap_debug:  * msgid 2,  origid 2, status InProgress
postmap: dict_ldap_debug:    outstanding referrals 0, parent count 0
postmap: dict_ldap_debug:   ld 0x55c861dd4b30 request count 1 (abandoned 0)
postmap: dict_ldap_debug: ** ld 0x55c861dd4b30 Response Queue:
postmap: dict_ldap_debug:    Empty
postmap: dict_ldap_debug:   ld 0x55c861dd4b30 response count 0
postmap: dict_ldap_debug: ldap_chkResponseList ld 0x55c861dd4b30 msgid 2 all 1
postmap: dict_ldap_debug: ldap_chkResponseList returns ld 0x55c861dd4b30 NULL
postmap: dict_ldap_debug: ldap_int_select
postmap: dict_ldap_debug: read1msg: ld 0x55c861dd4b30 msgid 2 all 1
postmap: dict_ldap_debug: ber_get_next
postmap: dict_ldap_debug: ber_get_next: tag 0x30 len 16 contents:
postmap: dict_ldap_debug: read1msg: ld 0x55c861dd4b30 msgid 2 message type search-result
postmap: dict_ldap_debug: ber_scanf fmt ({eAA) ber:
postmap: dict_ldap_debug: read1msg: ld 0x55c861dd4b30 0 new referrals
postmap: dict_ldap_debug: read1msg:  mark request completed, ld 0x55c861dd4b30 msgid 2
postmap: dict_ldap_debug: request done: ld 0x55c861dd4b30 msgid 2
postmap: dict_ldap_debug: res_errno: 0, res_error: <>, res_matched: <>
postmap: dict_ldap_debug: ldap_free_request (origid 2, msgid 2)
postmap: dict_ldap_debug: ldap_parse_result
postmap: dict_ldap_debug: ber_scanf fmt ({iAA) ber:
postmap: dict_ldap_debug: ber_scanf fmt (}) ber:
postmap: dict_ldap_debug: ldap_msgfree
postmap: dict_ldap_debug: ldap_free_connection 1 1
postmap: dict_ldap_debug: ldap_send_unbind
postmap: dict_ldap_debug: ber_flush2: 7 bytes to sd 6
postmap: dict_ldap_debug: ldap_free_connection: actually freed

Regards

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: Integrate Microsoft AD for user authentication and address Book

nafees29 wrote:

postmap -q user@example.com ldap:/etc/postfix/ad_virtual_mailbox_maps.cf and enable debug level 1 and when disable debug level on 0 then i did not see as per document.

Did not see what?

3

Re: Integrate Microsoft AD for user authentication and address Book

ZhangHuangbin wrote:
nafees29 wrote:

postmap -q user@example.com ldap:/etc/postfix/ad_virtual_mailbox_maps.cf and enable debug level 1 and when disable debug level on 0 then i did not see as per document.

Did not see what?

whit this command postmap -q user@example.com ldap:/etc/postfix/ad_virtual_mailbox_maps.cf
i am not getting error and result when debug level is set on 0 but when i set debug level on 1 then i see above out

please guide me

4

Re: Integrate Microsoft AD for user authentication and address Book

i am trying to integrate openldap as proxy to authenticate users from Microsoft Active Directory

5

Re: Integrate Microsoft AD for user authentication and address Book

nafees29 wrote:

i am trying to integrate openldap as proxy to authenticate users from Microsoft Active Directory

Dear Moderator,

I am waiting your response to fix mention issue.

Regards

6

Re: Integrate Microsoft AD for user authentication and address Book

nafees29 wrote:

i am trying to integrate openldap as proxy to authenticate users from Microsoft Active Directory

Our tutorial doesn't cover "openldap proxy", you're on your own.

nafees29 wrote:

"(objectclass=person)(userPrincipalName=md@mashospital.org)"

Try to search with this filter with ldap command line tool, e.g. ldapsearch.

7

Re: Integrate Microsoft AD for user authentication and address Book

ZhangHuangbin wrote:
nafees29 wrote:

i am trying to integrate openldap as proxy to authenticate users from Microsoft Active Directory

Our tutorial doesn't cover "openldap proxy", you're on your own.

nafees29 wrote:

"(objectclass=person)(userPrincipalName=md@mashospital.org)"

Try to search with this filter with ldap command line tool, e.g. ldapsearch.

Dear Zhang Huangbin

Please guide how to integrate LDAP with Microsoft AD.
unable to authenticate users from AD to iredmail and iredmail installed as backend with LDAP and all users are existing on AD please guide

8

Re: Integrate Microsoft AD for user authentication and address Book

You may need to tune the ldap query filter or returned attribute(s) to match your AD data.

9

Re: Integrate Microsoft AD for user authentication and address Book

Can you share LDAP query?

10

Re: Integrate Microsoft AD for user authentication and address Book

It is requested that please upgrade Integrate Microsoft Active Directory for user authentication and address book document on your site so it will help to others.

11

Re: Integrate Microsoft AD for user authentication and address Book

Dear @ZhangHuangbin,
I try following Iredmail guide to integrate with my Active directory but without success is there any easy step by step doing that .

any help will be valued

12

Re: Integrate Microsoft AD for user authentication and address Book

Dear @ZhangHuangbin,

pleas guide, my problem is not being solve.

Regards
Nafees Ahmed

13

Re: Integrate Microsoft AD for user authentication and address Book

nafees29 wrote:

Dear @ZhangHuangbin,

pleas guide, my problem is not being solve.

Regards
Nafees Ahmed

Dear @ZhangHuangbin,

integration with AD only work with A working Microsoft Windows (2000/2003) server, with Active Directory installed and working properly?

or

we can use any latest verion of Windows server?

Regards
Nafees Ahmed

14

Re: Integrate Microsoft AD for user authentication and address Book

My ldapsearch result as following:

# extended LDIF
#
# LDAPv3
# base <cn=users,dc=mashospital,dc=org> with scope subtree
# filter: (objectclass=*)
# requesting: ALL
#

# Users, mashospital.org
dn: CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: container
cn: Users
description: Default container for upgraded user accounts
distinguishedName: CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017103719.0Z
whenChanged: 20181017103719.0Z
uSNCreated: 5888
uSNChanged: 5888
showInAdvancedViewOnly: FALSE
name: Users
objectGUID:: Xl9r+nZVh0OHMhLpQmggwA==
systemFlags: -1946157056
objectCategory: CN=Container,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Allowed RODC Password Replication Group, Users, mashospital.org
dn: CN=Allowed RODC Password Replication Group,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Allowed RODC Password Replication Group
description: Members in this group can have their passwords replicated to all
read-only domain controllers in the domain
distinguishedName: CN=Allowed RODC Password Replication Group,CN=Users,DC=mash
ospital,DC=org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017104016.0Z
uSNCreated: 12405
uSNChanged: 12407
name: Allowed RODC Password Replication Group
objectGUID:: u5SLOmXbC0uLDLmAB04uOA==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGOwIAAA==
sAMAccountName: Allowed RODC Password Replication Group
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Denied RODC Password Replication Group, Users, mashospital.org
dn: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Denied RODC Password Replication Group
description: Members in this group cannot have their passwords replicated to a
ny read-only domain controllers in the domain
member: CN=Read-only Domain Controllers,CN=Users,DC=mashospital,DC=org
member: CN=Group Policy Creator Owners,CN=Users,DC=mashospital,DC=org
member: CN=Domain Admins,CN=Users,DC=mashospital,DC=org
member: CN=Cert Publishers,CN=Users,DC=mashospital,DC=org
member: CN=Enterprise Admins,CN=Users,DC=mashospital,DC=org
member: CN=Schema Admins,CN=Users,DC=mashospital,DC=org
member: CN=Domain Controllers,CN=Users,DC=mashospital,DC=org
member: CN=krbtgt,CN=Users,DC=mashospital,DC=org
distinguishedName: CN=Denied RODC Password Replication Group,CN=Users,DC=masho
spital,DC=org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017104016.0Z
uSNCreated: 12408
uSNChanged: 12436
name: Denied RODC Password Replication Group
objectGUID:: tbS1ir+E6kObduGgZI2kkA==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGPAIAAA==
sAMAccountName: Denied RODC Password Replication Group
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Read-only Domain Controllers, Users, mashospital.org
dn: CN=Read-only Domain Controllers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Read-only Domain Controllers
description: Members of this group are Read-Only Domain Controllers in the dom
ain
distinguishedName: CN=Read-only Domain Controllers,CN=Users,DC=mashospital,DC=
org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017105525.0Z
uSNCreated: 12422
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
uSNChanged: 12789
name: Read-only Domain Controllers
objectGUID:: 04KhQ3QgHEGInVMVfHh47w==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGCQIAAA==
adminCount: 1
sAMAccountName: Read-only Domain Controllers
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010101000000.0Z

# Enterprise Read-only Domain Controllers, Users, mashospital.org
dn: CN=Enterprise Read-only Domain Controllers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Enterprise Read-only Domain Controllers
description: Members of this group are Read-Only Domain Controllers in the ent
erprise
distinguishedName: CN=Enterprise Read-only Domain Controllers,CN=Users,DC=mash
ospital,DC=org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017104016.0Z
uSNCreated: 12432
uSNChanged: 12434
name: Enterprise Read-only Domain Controllers
objectGUID:: csYvTFLuR0G5klw4ubUL/g==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG8gEAAA==
sAMAccountName: Enterprise Read-only Domain Controllers
sAMAccountType: 268435456
groupType: -2147483640
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Cloneable Domain Controllers, Users, mashospital.org
dn: CN=Cloneable Domain Controllers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Cloneable Domain Controllers
description: Members of this group that are domain controllers may be cloned.
distinguishedName: CN=Cloneable Domain Controllers,CN=Users,DC=mashospital,DC=
org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017104016.0Z
uSNCreated: 12443
uSNChanged: 12445
name: Cloneable Domain Controllers
objectGUID:: LCyuxbx1VUiwE6Bu8qIpRg==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGCgIAAA==
sAMAccountName: Cloneable Domain Controllers
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Protected Users, Users, mashospital.org
dn: CN=Protected Users,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Protected Users
description: Members of this group are afforded additional protections against
  authentication security threats. See http://go.microsoft.com/fwlink/?LinkId=
298939 for more information.
distinguishedName: CN=Protected Users,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017104016.0Z
uSNCreated: 12448
uSNChanged: 12450
name: Protected Users
objectGUID:: ei3NrYqvm0Ws2FaBYkZvBg==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGDQIAAA==
sAMAccountName: Protected Users
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Key Admins, Users, mashospital.org
dn: CN=Key Admins,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Key Admins
description: Members of this group can perform administrative actions on key o
bjects within the domain.
distinguishedName: CN=Key Admins,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20211129135415.0Z
uSNCreated: 12453
uSNChanged: 35329121
name: Key Admins
objectGUID:: fg4UM1HtkUehw8PioVmVnQ==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGDgIAAA==
adminCount: 1
sAMAccountName: Key Admins
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20211129135415.0Z
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 16010714223648.0Z

# Enterprise Key Admins, Users, mashospital.org
dn: CN=Enterprise Key Admins,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Enterprise Key Admins
description: Members of this group can perform administrative actions on key o
bjects within the forest.
distinguishedName: CN=Enterprise Key Admins,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104016.0Z
whenChanged: 20181017104016.0Z
uSNCreated: 12456
uSNChanged: 12458
name: Enterprise Key Admins
objectGUID:: 0Ww9jO0swU2wOYI8sisGoA==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGDwIAAA==
sAMAccountName: Enterprise Key Admins
sAMAccountType: 268435456
groupType: -2147483640
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# DnsAdmins, Users, mashospital.org
dn: CN=DnsAdmins,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: DnsAdmins
description: DNS Administrators Group
distinguishedName: CN=DnsAdmins,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104055.0Z
whenChanged: 20181017104055.0Z
uSNCreated: 12486
uSNChanged: 12488
name: DnsAdmins
objectGUID:: 9BSFrjz9iUmZAFPTUce+OQ==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGTQQAAA==
sAMAccountName: DnsAdmins
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# DnsUpdateProxy, Users, mashospital.org
dn: CN=DnsUpdateProxy,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: DnsUpdateProxy
description: DNS clients who are permitted to perform dynamic updates on behal
f of some other clients (such as DHCP servers).
distinguishedName: CN=DnsUpdateProxy,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104055.0Z
whenChanged: 20181017104055.0Z
uSNCreated: 12491
uSNChanged: 12491
name: DnsUpdateProxy
objectGUID:: +2OjPopkf0Ono2Y8oaReSw==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGTgQAAA==
sAMAccountName: DnsUpdateProxy
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Access-Denied Assistance Users, Users, mashospital.org
dn: CN=Access-Denied Assistance Users,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Access-Denied Assistance Users
description: Members of this group are provided access-denied assistance when
it is enabled on this server. By default, this group allows all authenticated
  users to receive access-denied assistance.
distinguishedName: CN=Access-Denied Assistance Users,CN=Users,DC=mashospital,D
C=org
instanceType: 4
whenCreated: 20181224133110.0Z
whenChanged: 20181224133110.0Z
uSNCreated: 43261
uSNChanged: 43263
name: Access-Denied Assistance Users
objectGUID:: 9oUo4srpR0qVNkx+G5ikwQ==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGiQQAAA==
sAMAccountName: Access-Denied Assistance Users
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 16010101000001.0Z

# WSUS Administrators, Users, mashospital.org
dn: CN=WSUS Administrators,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: WSUS Administrators
description: Members of this group can administer the Windows Server Update Se
rvices role.
distinguishedName: CN=WSUS Administrators,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20201217151123.0Z
whenChanged: 20201217151123.0Z
uSNCreated: 21780080
uSNChanged: 21780083
name: WSUS Administrators
objectGUID:: tMR0OYslYUO39SavcY4feg==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG3gcAAA==
sAMAccountName: WSUS Administrators
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
dSCorePropagationData: 16010101000000.0Z

# WSUS Reporters, Users, mashospital.org
dn: CN=WSUS Reporters,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: WSUS Reporters
description: Members of this group can generate reports but cannot approve upd
ates or configure the Windows Server Update Services role.
distinguishedName: CN=WSUS Reporters,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20201217151124.0Z
whenChanged: 20201217151124.0Z
uSNCreated: 21780085
uSNChanged: 21780088
name: WSUS Reporters
objectGUID:: x+E6cKo6DUGvs8FmyHyCaA==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG3wcAAA==
sAMAccountName: WSUS Reporters
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
dSCorePropagationData: 16010101000000.0Z

# Administrator, Users, mashospital.org
dn: CN=Administrator,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: Administrator
description: Built-in account for administering the computer/domain
distinguishedName: CN=Administrator,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017103719.0Z
whenChanged: 20230415071844.0Z
uSNCreated: 8196
memberOf: CN=Group Policy Creator Owners,CN=Users,DC=mashospital,DC=org
memberOf: CN=Domain Admins,CN=Users,DC=mashospital,DC=org
memberOf: CN=Enterprise Admins,CN=Users,DC=mashospital,DC=org
memberOf: CN=Schema Admins,CN=Users,DC=mashospital,DC=org
memberOf: CN=Administrators,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 81224588
name: Administrator
objectGUID:: sv2ewef0sUmefeoJ7ersVA==
userAccountControl: 512
badPwdCount: 0
codePage: 0
countryCode: 0
badPasswordTime: 133260108616020705
lastLogoff: 0
lastLogon: 133260179065622881
logonHours:: ////////////////////////////
pwdLastSet: 133256795149229010
primaryGroupID: 513
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG9AEAAA==
adminCount: 1
accountExpires: 0
logonCount: 661
sAMAccountName: Administrator
sAMAccountType: 805306368
managedObjects: OU=Computers,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
managedObjects: CN=Administrators,CN=Builtin,DC=mashospital,DC=org
lockoutTime: 0
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
mSMQSignCertificates:: AQAAAPi0wgiGERuZKPEXI9I6kmU3SFr/47dET6dd9gTpTHx7igMAADC
CA4YwggJuoAMCAQICBKqlWlUwDQYJKoZIhvcNAQEFBQAwgYQxETAPBgNVBAceCABNAFMATQBRMQsw
CQYDVQQKHgIALTELMAkGA1UECx4CAC0xVTBTBgNVBAMeTABNAEEAUwBIAE8AUwBQAEkAVABBAEwAX
ABhAGQAbQBpAG4AaQBzAHQAcgBhAHQAbwByACwAIABtAGEAcwBoAC0AcAByAHQAMAAwADEwHhcNMj
EwNDA3MDU1MTM4WhcNMjkwNDA3MDU1MTM4WjCBhDERMA8GA1UEBx4IAE0AUwBNAFExCzAJBgNVBAo
eAgAtMQswCQYDVQQLHgIALTFVMFMGA1UEAx5MAE0AQQBTAEgATwBTAFAASQBUAEEATABcAGEAZABt
AGkAbgBpAHMAdAByAGEAdABvAHIALAAgAG0AYQBzAGgALQBwAHIAdAAwADAAMTCCASIwDQYJKoZIh
vcNAQEBBQADggEPADCCAQoCggEBANEQgH04kghUMqG8124HVleSNtmZJvATnVGwzgRzBQ97h9almC
BoQNk8nbMcYq4QtBSJQ+9R9gIKlTZkiOyXGENWwJQtuoy5QAa824ykGqZrjDYADIWavkxy3AiMfID
/W68z89VOlrKejcbpxgyY+0/VAw+q37W33Vho0lN5XWWYGRSQsAqwRjWLiFUrzsmSI4Hh6NkzfZkz
PugDmIdyBI8f10DCXvrorjQZvSuCPJMJQYKqH60UQ8U3WevsUUTEcxrNvNLry5iaU0ROrtymaQumN
Vjn5t70ydLFxHvu+Lr3nSuU/d2Nhod2rBzTnwwo7jhWaQLaVWr1Rj28T/ebQJsCAwEAATANBgkqhk
iG9w0BAQQFAAOCAQEAb6PTj1ulMtWsow1n2ZiqcdTnCkcOvBISEDB/S1gYtfiKYfjj8U3pedr+1UV
kJ0UautS57APrzhk4IkeVBqJTin3itUm/NvN16BA5GHPNUgoisIs9unpY4pS4O6Pa8D0Ke05syJfv
xYwjMBwRPjtrseVu7jHb2yVg+GkcifnzzeHsKV/dqIjsL2DFzWGSQFNSwNa16XJPi5UG/2x8+Z1yK
0I1zkWu0gj6BNszn8Uh5drRddARqK0rRbP8fLAMKeSgZoYiGr5D/4heTXc8IoMhGk5dIk1i20nJDC
9MZ9boNfWZjUpPcKBE7QSDS1lltIJRhG7yCkXn78OdnoQgTV5ncQ==
mSMQDigests:: +LTCCIYRG5ko8Rcj0jqSZQ==
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010101000000.0Z
lastLogonTimestamp: 133255857123283059

# Guest, Users, mashospital.org
dn: CN=Guest,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: Guest
description: Built-in account for guest access to the computer/domain
distinguishedName: CN=Guest,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017103719.0Z
whenChanged: 20181017103719.0Z
uSNCreated: 8197
memberOf: CN=Guests,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 8197
name: Guest
objectGUID:: Z5ZGg7bnMk+yRy+3guBwFA==
userAccountControl: 66082
badPwdCount: 1
codePage: 0
countryCode: 0
badPasswordTime: 132858300599057380
lastLogoff: 0
lastLogon: 0
pwdLastSet: 0
primaryGroupID: 514
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG9QEAAA==
accountExpires: 9223372036854775807
logonCount: 0
sAMAccountName: Guest
sAMAccountType: 805306368
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# DefaultAccount, Users, mashospital.org
dn: CN=DefaultAccount,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: DefaultAccount
description: A user account managed by the system.
distinguishedName: CN=DefaultAccount,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017103719.0Z
whenChanged: 20181017103719.0Z
uSNCreated: 8198
memberOf: CN=System Managed Accounts Group,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 8198
name: DefaultAccount
objectGUID:: 2q1z8lBsl02VlzESUOGsNg==
userAccountControl: 66082
badPwdCount: 0
codePage: 0
countryCode: 0
badPasswordTime: 0
lastLogoff: 0
lastLogon: 0
pwdLastSet: 0
primaryGroupID: 513
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG9wEAAA==
accountExpires: 9223372036854775807
logonCount: 0
sAMAccountName: DefaultAccount
sAMAccountType: 805306368
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# krbtgt, Users, mashospital.org
dn: CN=krbtgt,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: person
objectClass: organizationalPerson
objectClass: user
cn: krbtgt
description: Key Distribution Center Service Account
distinguishedName: CN=krbtgt,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017105525.0Z
uSNCreated: 12324
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
uSNChanged: 12788
showInAdvancedViewOnly: TRUE
name: krbtgt
objectGUID:: +maognWxoEWozrXgUf1dWg==
userAccountControl: 514
badPwdCount: 0
codePage: 0
countryCode: 0
badPasswordTime: 0
lastLogoff: 0
lastLogon: 0
pwdLastSet: 131842464158885870
primaryGroupID: 513
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoG9gEAAA==
adminCount: 1
accountExpires: 9223372036854775807
logonCount: 0
sAMAccountName: krbtgt
sAMAccountType: 805306368
servicePrincipalName: kadmin/changepw
objectCategory: CN=Person,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010101000000.0Z
msDS-SupportedEncryptionTypes: 0

# Domain Computers, Users, mashospital.org
dn: CN=Domain Computers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Domain Computers
description: All workstations and servers joined to the domain
distinguishedName: CN=Domain Computers,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017104015.0Z
uSNCreated: 12330
uSNChanged: 12332
name: Domain Computers
objectGUID:: b68BwljeuUuVXRalrBLRLQ==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGAwIAAA==
sAMAccountName: Domain Computers
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Domain Controllers, Users, mashospital.org
dn: CN=Domain Controllers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Domain Controllers
description: All domain controllers in the domain
distinguishedName: CN=Domain Controllers,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017105525.0Z
uSNCreated: 12333
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
uSNChanged: 12790
name: Domain Controllers
objectGUID:: +UBvcedZ0ku0ldy85X0WHg==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGBAIAAA==
adminCount: 1
sAMAccountName: Domain Controllers
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010101000000.0Z

# Schema Admins, Users, mashospital.org
dn: CN=Schema Admins,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Schema Admins
description: Designated administrators of the schema
member: CN=Administrator,CN=Users,DC=mashospital,DC=org
distinguishedName: CN=Schema Admins,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017105525.0Z
uSNCreated: 12336
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
uSNChanged: 12773
name: Schema Admins
objectGUID:: UZMSkwbgD0qMOzthB9FFYg==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGBgIAAA==
adminCount: 1
sAMAccountName: Schema Admins
sAMAccountType: 268435456
groupType: -2147483640
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010101000000.0Z

# Enterprise Admins, Users, mashospital.org
dn: CN=Enterprise Admins,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Enterprise Admins
description: Designated administrators of the enterprise
member: CN=Administrator,CN=Users,DC=mashospital,DC=org
distinguishedName: CN=Enterprise Admins,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017105525.0Z
uSNCreated: 12339
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
memberOf: CN=Administrators,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 12774
name: Enterprise Admins
objectGUID:: dr4stca9A0etAoELpV8t3w==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGBwIAAA==
adminCount: 1
sAMAccountName: Enterprise Admins
sAMAccountType: 268435456
groupType: -2147483640
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010101000000.0Z

# Cert Publishers, Users, mashospital.org
dn: CN=Cert Publishers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Cert Publishers
description: Members of this group are permitted to publish certificates to th
e directory
member: CN=AD,OU=Domain Controllers,DC=mashospital,DC=org
distinguishedName: CN=Cert Publishers,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017113420.0Z
uSNCreated: 12342
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
uSNChanged: 12813
name: Cert Publishers
objectGUID:: TzBP0+F7/k2JyPjW/DtK6Q==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGBQIAAA==
sAMAccountName: Cert Publishers
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Domain Admins, Users, mashospital.org
dn: CN=Domain Admins,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Domain Admins
description: Designated administrators of the domain
member: CN=MASH Meeting,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=mash lab,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=Asad Iqbal,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=M. Naji Ullah Khan,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=Mash CCTV,OU=Users,OU=Admin,OU=MAS MUX,DC=mashospital,DC=org
member: CN=Admin Bilal,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=Muhammad Sohail,OU=Users,OU=Pathology,OU=MAS MUX,DC=mashospital,DC=
org
member: CN=Ahsan Ali Ansari,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=Muhammad Bilal Khan,OU=Users,OU=IT,OU=MAS MUX,DC=mashospital,DC=org
member: CN=Administrator,CN=Users,DC=mashospital,DC=org
distinguishedName: CN=Domain Admins,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20230201073330.0Z
uSNCreated: 12345
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
memberOf: CN=Administrators,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 76077705
name: Domain Admins
objectGUID:: OfZoSwpynE+Lu2hOnlfSYw==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGAAIAAA==
adminCount: 1
sAMAccountName: Domain Admins
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20200213064306.0Z
dSCorePropagationData: 20200213054454.0Z
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 16010101000000.0Z

# Domain Users, Users, mashospital.org
dn: CN=Domain Users,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Domain Users
description: All domain users
distinguishedName: CN=Domain Users,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017104015.0Z
uSNCreated: 12348
memberOf: CN=Users,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 12350
name: Domain Users
objectGUID:: xeO6XpCJBU+QM/Ji2hngMA==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGAQIAAA==
sAMAccountName: Domain Users
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Domain Guests, Users, mashospital.org
dn: CN=Domain Guests,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Domain Guests
description: All domain guests
distinguishedName: CN=Domain Guests,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017104015.0Z
uSNCreated: 12351
memberOf: CN=Guests,CN=Builtin,DC=mashospital,DC=org
uSNChanged: 12353
name: Domain Guests
objectGUID:: TOY9LIQxZEmdPDnloHAn8w==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGAgIAAA==
sAMAccountName: Domain Guests
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# Group Policy Creator Owners, Users, mashospital.org
dn: CN=Group Policy Creator Owners,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: Group Policy Creator Owners
description: Members in this group can modify group policy for the domain
member: CN=Administrator,CN=Users,DC=mashospital,DC=org
distinguishedName: CN=Group Policy Creator Owners,CN=Users,DC=mashospital,DC=o
rg
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20181017104015.0Z
uSNCreated: 12354
memberOf: CN=Denied RODC Password Replication Group,CN=Users,DC=mashospital,DC
=org
uSNChanged: 12391
name: Group Policy Creator Owners
objectGUID:: r1W3LKjTCk6V41tbHc29FA==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGCAIAAA==
sAMAccountName: Group Policy Creator Owners
sAMAccountType: 268435456
groupType: -2147483646
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# RAS and IAS Servers, Users, mashospital.org
dn: CN=RAS and IAS Servers,CN=Users,DC=mashospital,DC=org
objectClass: top
objectClass: group
cn: RAS and IAS Servers
description: Servers in this group can access remote access properties of user
s
member: CN=APEX01,CN=Computers,DC=mashospital,DC=org
distinguishedName: CN=RAS and IAS Servers,CN=Users,DC=mashospital,DC=org
instanceType: 4
whenCreated: 20181017104015.0Z
whenChanged: 20210406073304.0Z
uSNCreated: 12357
uSNChanged: 24887451
name: RAS and IAS Servers
objectGUID:: 1ttYxCmlJEmUtfrsJGpQ+w==
objectSid:: AQUAAAAAAAUVAAAA1ThceGUfr0RHxXoGKQIAAA==
sAMAccountName: RAS and IAS Servers
sAMAccountType: 536870912
groupType: -2147483644
objectCategory: CN=Group,CN=Schema,CN=Configuration,DC=mashospital,DC=org
isCriticalSystemObject: TRUE
dSCorePropagationData: 20191017054705.0Z
dSCorePropagationData: 20181217120547.0Z
dSCorePropagationData: 20181208045854.0Z
dSCorePropagationData: 20181025132149.0Z
dSCorePropagationData: 16010714223649.0Z

# search result
search: 2
result: 0 Success

# numResponses: 29
# numEntries: 28
[root@mail-2 ~]#

15

Re: Integrate Microsoft AD for user authentication and address Book

Now, postmap results are good as per documents but dovecot is not authenticating the user:

Result as following:
Trying ::1...
Connected to localhost.
Escape character is '^]'.
* OK [CAPABILITY IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE IDLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN] Dovecot ready.
. login nafees.ahmad@mashospital.org nafees-123
* OK Waiting for authentication process to respond..
. NO [UNAVAILABLE] Temporary authentication failure. [mail-2.mashospital.org:2023-04-16 00:01:37]
* BYE Disconnected for inactivity.
Connection closed by foreign host.

Please guide where am i wrong?

16

Re: Integrate Microsoft AD for user authentication and address Book

- Please turn on debug mode for auth in Dovecot config file dovecot.conf for easier troubleshooting. FYI https://docs.iredmail.org/debug.dovecot.html

- Every AD installation is different, so our tutorial can only cover most cases and may fail with your AD. But the procedure and setup are almost same, you just need to tune the LDAP server address + port, bind dn, bind password, search base dn, also most importantly, you must figure out which ldap attribute in AD you want to return by the ldap query. That's it.

Use command line tool "ldapsearch" or other GUI ldap client tool to query AD, it will be easier to understand what data you get in return with the ldap query, or what AD stores.