<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Easier Microsoft Active Directory Connectivity in OpenSSO Express 8</title>
	<atom:link href="http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/</link>
	<description>Pat Patterson on the Cloud, Identity and Single Malt Scotch</description>
	<lastBuildDate>Mon, 13 May 2013 04:45:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Pat Patterson</title>
		<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/comment-page-1/#comment-757</link>
		<dc:creator>Pat Patterson</dc:creator>
		<pubDate>Thu, 12 Nov 2009 21:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/#comment-757</guid>
		<description><![CDATA[Hi Robert - I&#039;m no longer working on OpenSSO (I left Sun a couple of months ago now), but I&#039;ll pass your comment on to the OpenSSO team. Thanks!]]></description>
		<content:encoded><![CDATA[<p>Hi Robert &#8211; I&#8217;m no longer working on OpenSSO (I left Sun a couple of months ago now), but I&#8217;ll pass your comment on to the OpenSSO team. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Kelly</title>
		<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/comment-page-1/#comment-756</link>
		<dc:creator>Robert Kelly</dc:creator>
		<pubDate>Thu, 12 Nov 2009 20:22:44 +0000</pubDate>
		<guid isPermaLink="false">http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/#comment-756</guid>
		<description><![CDATA[Hi Pat,
I had a slight issue with the new feature.
We have multiple AD Sites and it picked a server in a remote site vs. a local one.

Before the LDAP lookup, a Site lookup should really be performed, probably based on the subnet the server is in and then finding out which LDAP servers are in that site.
In a domain with multiple Sites, you could end up configuring an AD connection to a server in a remote site over a potentially slow link vs. your local servers.]]></description>
		<content:encoded><![CDATA[<p>Hi Pat,<br />
I had a slight issue with the new feature.<br />
We have multiple AD Sites and it picked a server in a remote site vs. a local one.</p>
<p>Before the LDAP lookup, a Site lookup should really be performed, probably based on the subnet the server is in and then finding out which LDAP servers are in that site.<br />
In a domain with multiple Sites, you could end up configuring an AD connection to a server in a remote site over a potentially slow link vs. your local servers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pat Patterson</title>
		<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/comment-page-1/#comment-573</link>
		<dc:creator>Pat Patterson</dc:creator>
		<pubDate>Mon, 21 Sep 2009 03:05:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/#comment-573</guid>
		<description><![CDATA[Hi hzhao, Yes, you can still specify AD hostname and port if you want to.]]></description>
		<content:encoded><![CDATA[<p>Hi hzhao, Yes, you can still specify AD hostname and port if you want to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hzhao</title>
		<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/comment-page-1/#comment-572</link>
		<dc:creator>hzhao</dc:creator>
		<pubDate>Mon, 21 Sep 2009 02:01:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/#comment-572</guid>
		<description><![CDATA[hi, pat. can I still specify the host and port to connect to AD? 
actually, in my environment, the data store is ADAM not AD, but the schemas are identical to AD.]]></description>
		<content:encoded><![CDATA[<p>hi, pat. can I still specify the host and port to connect to AD?<br />
actually, in my environment, the data store is ADAM not AD, but the schemas are identical to AD.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pat Patterson</title>
		<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/comment-page-1/#comment-11</link>
		<dc:creator>Pat Patterson</dc:creator>
		<pubDate>Wed, 16 Sep 2009 02:23:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/#comment-11</guid>
		<description><![CDATA[&lt;p&gt;Hi Jonathan - you specify a *domain*, not an individual domain controller. I guess if you have the inter-domain trusts set up correctly in the forest, then it will all work...&lt;/p&gt;
]]></description>
		<content:encoded><![CDATA[<p>Hi Jonathan &#8211; you specify a *domain*, not an individual domain controller. I guess if you have the inter-domain trusts set up correctly in the forest, then it will all work&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan G.</title>
		<link>http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/comment-page-1/#comment-10</link>
		<dc:creator>Jonathan G.</dc:creator>
		<pubDate>Wed, 16 Sep 2009 00:18:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.superpat.com/2009/09/15/easier-microsoft-active-directory-connectivity-in-opensso-express-8/#comment-10</guid>
		<description><![CDATA[&lt;p&gt;Can I specify an AD forest, rather than DomainController,  or can I not see the forest for the (LDAP) trees? :)&lt;/p&gt;
]]></description>
		<content:encoded><![CDATA[<p>Can I specify an AD forest, rather than DomainController,  or can I not see the forest for the (LDAP) trees? <img src='http://blog.superpat.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
