User guide
the user’s password must be changed after this setting is changed. In addition, the
Active Directory server addresses must be resolvable to their host names via DNS.
When this is not checked, the LDAP protocol will be used.
g. Click Enable Chasing of Referrals to allow the Active Directory server to refer
DSView software clients to additional directory servers.
• Click Select an Active Directory Search Mode to have the AD service access the
global catalog for the specified domain name. The search includes the
"TokenGroups" attribute of the ObjectClass=user. This search is faster but only
retrieves the nested groups SIDs; subsequent calls must be made to find the group
name and specific SIDs. This is recommended for performance.
• Click Allow users and groups from newly discovered trusted forests to allow
logins by users that belong to the authentication service forest or its discovered
trusted forests. If enabled, the DSView will discover all trusted forests in the
Active Directory service.
• Click Use Recursion to search groups to include all sub-containers in your Active
Directory search.
h. Click Next.
If you selected Use SSL in Certificate-based Trust Mode, go to step 6.
If you selected Do Not Use SSL or Use SSL in Trust All Mode, go to step 8.
6. The DSView server will try to find a server that has a trusted certificate chain (see System
certificate policy and trust store on page 52). If no trusted certificate chain is found, then
the Accept Certificate window will open and list all servers that belong to the domain. It
will also list the reasons for rejection of the certificate chain.
7. Click Next to accept the certificate.
8. The Select Browsing Method window will open.
Click Browse Anonymously to browse users on the external Active Directory
authentication server.
-or-
Click Browse with user credentials to browse users on the external Active Directory
authentication based on credentials configured on the server. If this option is selected,
do the following:
a. Type the username for an Active Directory account that has browse rights in the User
Name field. The login ID must be entered in case sensitive text if the Active Directory
92 DSView™ 4 Installer/User Guide