slow performance with ADSelfService Plus
I am trying out ADSS Plus in my environment. We are putting it in our vCloud Air cloud, which is just a virtualized vSPhere based public cloud. We have the VM running the code setup as a 2vCPU 4GB of memory. When I look at task manager, I don't see anything out of control for the VM OS level. The problem is that when I login using an Domain account it takes 15-20 seconds to login. WHen I login as the admin account, it will only take 1-2 seconds. I do have the backend AD sitting on the same network,
How do I integrate ADSelfService Plus with SharePoint 2013
Is there any documentation on how to use ADSelfService Plus with SharePoint 2013? If so can I get that info?
Integration of ADSelfService Plus with SharePoint server
Version 4.5 Build 4510: (25/April/2011) has this enhancement: Integration of ADSelfService Plus with SharePoint server Could you explain a little more about this feature? What it does, how it works, how to configure it, etc.? Thanks.
Could not connect to SMTP hosts: vm01mail.nautic-group.com, port 25
Hi, getting above error. Configuring AD Self service plus 1st attempt. On a standalone desktop connected to the same network. Domain registration works, password can be reset/etc. When configuring SMTP Mail settings I am getting this error. Connection security - none. Tested with my own email address/password, exchange. Port 25 example.mydomain.com Telnet to port 25 works fine. Windows FW has been disabled, no other FW installed. Please advise? regards, Raj
How to disable Password Expiry notification email.
Hi. We are using an old version of ADSelfService Plus tool. (Verison 4.5 build 4571). We had an existing password expiry notification schedule setup. However, we no longer need this and have disabled it by clicking on the disable/enable toggle button. But the user are still receiving the notification. So i then simply deleted the notification schedule. The users are still getting the notification emails. How do i stop this email notification? Do i have to reboot the server? Or is there a service
SMS not send
Hello, When a user tries to unlock/reset password through the web interface he/she doesn't get a SMS with the verification code on their mobile phone. We can send a test sms to the same number from the admin page though. Settings: Clickatell SMS gateway activated (if it isnt activated we cant send a test sms through the admin page) SMS credits ( there are enough credits available) Please help me out because we cannot implement this package for our organization this way.
ADSelfService Plus 5.3 Build 5304
Hi, We are glad to announce the release of ADSelfService Plus’s latest build – 5304. This release includes some major bug fixes. Issues Fixed: Issue in accessing the self-service portal through GINA due to a script error. XSS vulnerabilities have been fixed for improved security. Issue in enrolling users from external database when the total number of users exceed a certain limit. Issue in license management while accessing unowned licenses. SSO issue which prevented Mac users from accessing the
How to use certificate generate by my internal CA
Hi, i want to know how to use certificate generate by my internal CA. I generate CSR on ADSelfService, and create certificate on my internal CA, and follow all the step's(put CA certificate and generated certificate on same keystore and copy to conf folder), but when i try to access ADSelfService using https give the message that certificate is not trusted. Regards, Gerson Jamal
What's the Purpose of Linked Accounts?
Linking accounts (say a local AD account with O365) doesn't seem to serve any purpose. The documentation on this feature is slim so I would appreciate some clarification. Cheers, Kyle
Security Questions requirements are too restrictive
I've just rolled out AD Self Service at my organization. I keep getting users reporting that for several of the questions there are restrictions to have 5+ characters when the question should realistically allow for fewer. For example if a user selects "What is your favorite color?" as a question, it requires 5 or more characters. So completely valid answers: Red, Blue, etc... will not work. I understand the need to require a minimum character length so that fields are not left blank, but not
Passwrod Expiry Notification Change replyto Email
running ADSelfService Plus Password Expiration Notification Tool, v 5.3 build 5303 free edition how do I locate and change the exchange server settings? thanks
change replyto address - Expiry Notification Tool
running ADSelfService Plus’ Password Expiry Reminder Tool, v 5.3 free edition. I'm trying to change the "Reply To" address that is included in the email notifications. it currently says noreply@adselfserviceplus.com and i'd like to change this. I can't seem to find how to change exchange server settings in general either. Thanks for any help that can be provided.
GINA not pushing correct URL on client computers
Hi, We're having an issue where the GINA does not update or push the correct configuration to the client. We tested the app with HTTP and use the server name URL then decided to enable SSL with a different name for the web server. This new URL, even though updated properly in the web interface is not pushed on the client and therefore the client machine gets a invalid certificate error since the name of the server that is in the registry does not match the certificate. IS there a way to force the
License count
Dear all, We have evalute the ADSeldService feature, one question how is the license count toward domain users. Our company policy will never delete users account and only put them to disable after they left, would it count toward domain users license? Regards, Daniel
QR Code Image
I am trying to figure a way to change the address within the QR image. The server address that is in the QR image is the Server name and I need it to be the URL that is accessible from the internet. The server name is only accessible from our internal network.
Installation SSL FOR ADSelfService
Hi, We are using ADSS inside our domain. How to generate keystore file from our internal CA, which script or keytool can we use? Thanks, E.
ADSelfService Enroll.hta
What permissions it should have an account to download it to ADSelfService Enroll.hta to SYSVOL, where it is described in the documentation?
Where do I change the email address?
Hi, We have changed our contact email address and I would like to update the same on SelfService but I can't find it
Change "Permission Denied. Kindly contact your Administrator" message when un-enroled users login
I would like to know how to change the "Permission Denied. Kindly contact your Administrator" when a user who is not enrolled tries to reset their password? Would like to change it say something like "You have not enrolled, please enrol before using this service2? Also, on the Reset Password and Unlock Account login screens, I want to change the text next to the username field that shows "(Example : Jsmith)". Our usernames are first name.surname and want the example to show this. Any ideas?
After enabling SSL on ADSelfService, Single Sign On does not work and asks for credentials....
We have ADSelfService work with single-sign-on on HTTP without any issues. I decided to purchase a SSL certificate and assign an external domain to the server in order to have it accessible from the internet. After the wonderful help from MangeEngine support, I was able to get SSL working on the site with the port 9251. Now the issue is that when I access the site from any computer internally, the single sign on does not work any more and I get prompted to enter my domain credentials before been
ADSelfService Plus 5.3 Build 5303
Hi, We are glad to announce the release of the latest build of ADSelfService Plus – 5303. This release brings a major new feature that empowers remote users – cached password update. Feature: Now update local cached password when remote users reset their passwords in Active Directory through the GINA/CP client. IMPORTANT NOTE: Existing Customers can upgrade to the latest build by downloading the ADSelfService Plus Service Pack 5.3 SP 0.3 from the link below: http://www.manageengine.com/products/self-service-password/service-pack.html
Which domain controller(s) should I be using
Need some help from support and would be helpful to hear from other folks using the product. I have set the product to only use the primary domain controller emulator PDCe. The thought behind this is: When an account is locked out no matter where, the lockout is replicated from the local site DC up to the PDCe right away This makes unlocks against the PDCe always work as the PDCe has seen the lockout right away When an account is unlocked, or password reset, the user then tries to login to Windows.
Adselfservice_enroll.hta not working
Hi, I've created a domain strategy and I 've configured force enrollment linked to this strategy. I 've noticed that the Adselfservice_enroll.hta script is stored in the sysvol directory on domaine controler . What is exactly the mechanism to copy the script on the sysvol ?whose user is copying the script? When i logon PC there is no windows message to force enrollment. How Adselfservice_enroll.hta is triggered ? What should i do ? Thanks Franck
Password expires one day early...why?
The password expiration notification is off by a day. It informed a user that his password will expire on 7/16 but it actually expired on 7/15. we verified this by using Sysinternals tools - lockoutstatus. Is there a setting i can change to set the right expiration date?
Password Change notification
Hello, I'm trying to setup the password reset/change/unlock email notification. I have the server information setup and I can send a test email successfully to our admin account. I ran a reset on a test account and I did not receive the email notification. I thought to look in the personal information portion, but I can't see where an email address would go. Did I miss something?
ADSelfService Plus 5.3 Build 5300 Service Pack Install hangs at 98% Post invocation progress
ADSelfService Plus 5.3 Build 5300 Service Pack Install hangs at 98% Post invocation progress. Trying to update from 5.2.6 using ManageEngine_ADSelfService_Plus_5_2_0_SP-9_9_0.ppm on Windows Server 2008 R2. Yes, ManageEngine service is stopped and stopDB.bat was run. Oddity noted: there is a second 'Installation Wizard' window behind this one which shows no progress. Anyone else solved this issue?
Which SSL Certificate file to use
I used RapidSSL for my certificate. I submitted my CSR data online, by coping and pasting the contents of the CSR file. They then supplied me with some download options after they generated and issued the certificate. First, I have two possible formats to download the certificate: Either to download a certificate in PKC7S format, or a X.509 certificate. Second, I have the three additional options that I can choose: 1. Plesk bundle 2. Certificate Issuer 3. Apache bundle Would it be correct that I
SSL Certificate Web Server Type
I am attempting to setup an SSL Certificate. I have generated my data from the ADSSP certificate tool, but now my ISP that I am getting the certificate from, have asked what my "Web Server Type" is? ADSSP is installed on a Windows 2008R2 server, so the closest to this in their options is "Microsoft IIS 5+ or later" or is it something else? I have noticed people have mentioned tomcat in some of the queries in the forum, so do I choose that? "
Schedule Reports
Running ADSelfService Manager Build 5300 Log in as Admin click on Reports TAB Click on Schedule Reports top right Get the following error; Sorry,the page you requested was not found. Back | Sign Out Any ideas? Thank you in advance
ADSelfService Plus 5.3 Build 5300
Hi, We are glad to announce the release of the latest version of ADSelfService Plus – 5.3 (build 5300). This new version introduces ‘Help Desk Assisted Self-password Reset and Account Unlock’ along with some major enhancements and bug fixes. Features: Help desk assisted self-password reset and account unlock using Active Directory attributes as security questions to verify user identity. Enhancements: Updates Java Runtime Environment package to version 7. Supports TLS 1.2 for heightened security.
Password history enforcement
We have deployed ADSelfservice Plus and are using it successfully. However we just discovered what could be a major issue. It appears the product allows users to re-use passwords, because it doesn't look at the AD password history. I found and checked the box on the Policy Configuration screen, under Reset & Unlock, that says "Enforce Active Directory Password history settings during password reset", but it doesn't seem to work. In testing I can reset a password, then run again to reset to a new
Bad Notification Message When Linking Accounts Fails
Hello ADSelfService, We have a IBM AS400 system and would like to give our users the possibility of reseting/unlocking their AS400 account's with the self-service functionalities. When trying to link accounts, the system throws a bad message if a user enters the wrong credentials: {"TEXT_KEY":"ads.common.error.invalid_credential","SEVERITY":"severe","ERROR_CODE":7,"ERROR_KEY":"INVALID_USER_OR_PASS","DISPLAY_TEXT":"Invalid User Name or Password"} The normal user won't understand what is going on.
setting up SSL via tomcat/adssp
So, I've created a new java keystore using the keytool app, I've imported our companies public and signed certificates to that keystore. I've copied the keystore to the /conf/ folder and renamed it to selfservice.keystore. I've adjusted the server.sml to point to the new keystore and added a few recommended options to get our certs to load: <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" name="SSL" maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
Trying to implement SSL for ADSSP
So, I've created a new java keystore using the keytool app, I've imported our companies public and signed certificates to that keystore. I've copied the keystore to the /conf/ folder and renamed it to selfservice.keystore. I've adjusted the server.sml to point to the new keystore and added a few recommended options to get our certs to load: <Connector port="8443" protocol="org.apache.coyote.http11.Http11NioProtocol" name="SSL" maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
Problems Updating Secutiry Que & Ans from IE
Hello ADSelfService, IE is a commonly used browser in our environment, and in the majority of cases, some users are restricted to use other browsers to access the network where our ADSelfService Server is installed, whitch makes IE a very important browser for this tipe of users. We noticed that users aren't being able to update their Security Q&A from IE, but in turn, if an other browser is used (i.e FireFox) they manage to update the Q&A. Is there a way to troubleshoot this? Thanks & Regards,
AD Self Service Plus icon missing
After installing the product on a 2012 server, it ran. I made changes that would allow for SSL. I had to restart the server in order to complete the changes. After I shutdown the AD SelfService Plus server it would not come back on. Then I remembered I had set it to run when windows starts. So I rebooted the entire server. It still will not come up. I looked in the install directory, but there are no exe's to run. Additionally, there is no program called AD SelfService Plus in the start menu.
Password Expiry Notification test email?
I have had the password notifier setup for a few years now without issue, getting ready to update the email verbage and was wonder if there is a way to send myself a test message with the updated verbage from the notifier to see how the format looks in email? thanks in advance! -Kevin
Password Expiry Admin Mail Delivery Notification
Hi Team, We have just implemented your password expiry module and its excellent. However we only seem to ever get the admin mail delivery notification if we actually start the Client portal application. I would have thought the ADSelfService "service" (we installed the service) would perform this task and not rely on a foreground application. Would this then also apply to the notification email going out to end users? Cheers
Enable Hide Self-Service Admin Login
Hello I unknowingly enabled the 'Hide Self-Service Admin Login' without providng exceptions. How do I re-enable it or be able to login as admin ?
Virtual Machines and Thin Clients
Hello, Is the AD SelfService plus available for Virtual Machines? and if so, what about for use on thin clients/PanoLogic with a non-windows logon? For Example: Not all of our end users log in at a windows logon screen. Some have to log into the PanoLogic screen which then authenticates both Pano and Windows logon. Thank You, Marissa Defino
Next Page