<?xml version="1.0"?>
<rss version="2.0">
<channel>
<title>Thycotic Community - Secret Server - Remote password changing further details requested - Messages</title>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=286</link>
<description>Thycotic Community - Secret Server - Remote password changing further details requested - Messages</description>
<language>en-us</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>Jitbit AspNetForum</generator>
<pubDate>Thu, 15 Jul 2010 11:31:55 GMT</pubDate>
<lastBuildDate>Thu, 15 Jul 2010 11:31:55 GMT</lastBuildDate>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=286</link>
<title>Message from hao</title>
<description><![CDATA[In addition, you do not have to turn off AD Password expiring, but you should set up your  RPC scheduler such that the password-changing interval is shorter than your AD password age requirement. In another words, if your AD expires a password after 30 days, your RPC should work at a 30-day or shorter interval. ]]></description>
<pubDate>Thu, 15 Jul 2010 11:31:55 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=286</link>
<title>Message from hao</title>
<description><![CDATA[Hi Adam,<br/><br/>An top-level overview can be found in this Knowledge Base Article:<br/>&lt;a href="http://support.thycotic.com/KB/a92/what-is-remote-password-changing-for-service-accounts.aspx?KBSearchID=4997"&gt;http://support.thycotic.com/KB/a92/what-is-remote-password-changing-for-service-accounts.aspx?KBSearchID=4997&lt;/a&gt;<br/><br/>The Dependency Finder will ask you for an ActiveDirectory credential that will be used to find all computers on the domain in order to create a list of computers to search. This search is done through an LDAP query, so your web server will need access through the LDAP ports to the Domain Controller. In addition, you can enter the specific computer names that you would like to search to limit the search result and bypass the LDAP query. Once Dependency Finder has the list of target computers to search, it uses Windows Management Instrumentation (WMI) to query the target machine for a list of Windows Services that are started with the Identity matching the credentials as defined in the Secret. The WMI query requires the WMI ports be open. See this KB Article for adding a Firewall exception (&lt;a href="http://support.thycotic.com/KB/a48/enabling-wmi-for-use-with-dependency-finder.aspx?KBSearchID=4997"&gt;http://support.thycotic.com/KB/a48/enabling-wmi-for-use-with-dependency-finder.aspx?KBSearchID=4997&lt;/a&gt; ). For each machine, the services are returned so they can be added as dependencies. Once the list of services is compiled the user must select a Secret with Privilege Account that has permission to change the Identity and restart the service on that machine. After the dependencies are setup and the Secret is enabled for RPC, the remote password changer will change and restart the dependencies at the same time that the password of the account stored in the Secret is changed (such as for an Active Directory Secret storing a Service Account credential in your question).<br/><br/>Best Regards,<br/>Hao]]></description>
<pubDate>Thu, 15 Jul 2010 11:23:02 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=286</link>
<title>Message from Adam D</title>
<description><![CDATA[Also should you have AD password expiring turned off and just use Secret Server password expiring timer?]]></description>
<pubDate>Wed, 14 Jul 2010 15:39:18 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=286</link>
<title>Message from Adam D</title>
<description><![CDATA[Hi, we are about to implement the remote password changing feature of SS and would like some advanced documentation if you have it.<br/><br/>I still have some confusion on how it works, the user guide doesnt go into too much details.<br/><br/>Some of our questions are: <br/><br/>What happens behind the scenese?<br/>Does the password reset the AD password and then all dependencies like a service account on a remote computer?<br/>What are the necessary ports that need to be opened for this to work?<br/>Any other information that may be helpful would be great<br/><br/>Thank you,<br/>Adam]]></description>
<pubDate>Wed, 14 Jul 2010 15:38:04 GMT</pubDate>
</item>
</channel>
</rss>
