MSDSS Password Sync Error

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

I'm having trouble with password sync from AD to NDS using MSDSS with a two
way session. When a password sync is attempted during forward sync the
following error is logged:

The password for user "O=1st_Source/OU=MSDSTEST/OU=TestOu2/CN=testuser3" is
not available for synchronization. A password has NOT been generated for the
user because a password exists on the user already. If the user changes their
Active Directory password, the new password will be available for
synchronization. The user will be forced to change their password at next
logon.

The event source is MSDSS is event ID is 0. Environment is Windows 2003,
Novell Client 4.9 SP1, SFN 5.03 (tried SP1 and SP2 for SFN.)

I saw one other metion of this error and it suggested registering
dsspwd.dll. I tried that, but no change.

Thanks in advance for any advice!
 
UPDATE: Here's the solution:

This problem was related to the "Store Passwords Using Reversible
Encryption" policy setting.

Although I am unable to find documentation of this, the installation of

MSDSS appears to edit the Default Domain Policy and adds a policy
of "Store Passwords Using Reversible Encryption=Enabled" In this
case there was already a Default Domain policy setting this as disabled

before MSDSS was installed. Changing this to enabled fixed the
password
sync issue and passwords are now properly synced over to eDir.
 
Back
Top