Scope
vSEC:CMS integrates with Active Directory (AD) and Microsoft (MS) CA across various workflows. This document details which user contexts execute AD lookups for each specific vSEC:CMS use case.
Admin/Agent AD Lookups
This section will describe the user contexts when performing lifecycle operations from the Admin/Agent applicaiton on a client host.
Configuration Option 1
If the AD connection used in the credential template is configured like below then the current logged on Windows account that the vSEC:CMS application is running under will perform the AD lookup.
Important: The AD lookup will be performed from the client host that the Admin/Agent applicaiton is running on in this case.
For example, I log onto my client host with a Windows account vseccms\jdoe then the AD lookups in this case will be performed by the Windows account vseccms\jdoe.
Configuration Option 2
If the AD connection used in the credential template is configured like below then the Windows account configured in the connection will perform the AD lookup (vseccms\administrator in this example).
Important: The AD lookup will be performed from the client host that the Admin/Agent applicaiton is running on in this case.
vSEC:CMS User AD Lookups
This section will describe the user contexts when performing lifecycle operations from the vSEC:CMS User applicaiton on a client host.
Configuration Option 1
If the AD connection used in the credential template is configured like below then the AD lookups will be performed by the Windows service account that vSEC:CMS service is running under.
Important: The AD lookup will be performed from the server where vSEC:CMS is running on in this case.
Configuration Option 2
If the AD connection used in the credential template is configured like below then AD lookups will be performed by the AD account configured (vseccms\administrator in this example).
Important: The AD lookup will be performed from the server where vSEC:CMS is running on in this case.
Admin/Agent AD Lookups with MS CA
During vSEC:CMS certificate lifecycle operations, vSEC:CMS performs AD lookups when communicating with the MS CA. This section will describe the user context that will perform the AD operations when certificate related operations are being perormed.
Configuration Option 1
If the MS CA connection used in the credential template is configured like below then the AD lookups performed will be performed by the Windows service account that vSEC:CMS service is running under.
Important: The AD lookup will be performed from the server where vSEC:CMS is running on in this case as Proxy through server is enabled. If you disable Sign server side (which is not recommended) and then disable Proxy through server then the AD lookups will be performed from the client host that the Admin/Agent application is running on.
Note: Accessing or editing the CA connection settings (as configured above) requires the active Windows user context under which the application executes to possess explicit Read and Enroll rights on the target Certification Authority.
Configuration Option 2
If the MS CA connection used in the credential template is configured like below then the Windows account configured in the connection will perform the AD lookup (vseccms\ca-account in this example).
Important: The AD lookup will be performed from the server where vSEC:CMS is running on in this case as Proxy through server is enabled. If you disable Sign server side (which is not recommended) and then disable Proxy through server then the AD lookups will be performed from the client host that the Admin/Agent application is running on.
Note: To view or edit CA connection settings, the Windows user account specified in the Windows logon name field must have explicit Read and Enroll permissions on the target Certification Authority.
Additional Tips
Enable Event Viewer Capturing
From Event Viewer you can check what AD searches have been performed along with the accounts used by configuring on DC the following in registry:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters]
DWORD: Expensive Search Results Threshold value 1
DWORD: Inefficient Search Results Threshold value 1
And
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics]
DWORD: 15 Field Engineering value 5
Then from Event Viewer you can see what seraches have been performed by what user.
Powershell Script
When troubleshooting directory lookup issues, Windows PowerShell is a quick, effective tool. The sample script below can be adapted to your specific environment.
Where to run it?
- vSEC:CMS Server: Tests directory connectivity directly from the host machine.
- vSEC:CMS Clients: Tests lookups from machines running vSEC:CMS Admin, Agent, or User applications.
# 1. Target DC and Lookup Settings
$TargetDC = "my-dc.example.com"
# Provide sAMAccountName of user that will be looked up
$SearchUser = "myuser"
# 2. Prompt for credentials that will connect to DC to perform the lookup
$Cred = Get-Credential
# 3. Build the LDAP root path pointing directly to the target DC
$DomainDN = "DC=example,DC=com" # Adjust to match your AD domain structure
$LdapPath = "LDAP://$TargetDC/$DomainDN"
# Extract username and plain-text password from PSCredential object
$Username = $Cred.UserName
$Password = $Cred.GetNetworkCredential().Password
try {
# 4. Establish LDAP Connection using explicit credentials
$DirectoryEntry = New-Object System.DirectoryServices.DirectoryEntry(
$LdapPath,
$Username,
$Password,
[System.DirectoryServices.AuthenticationTypes]::Secure
)
# 5. Execute Searcher
$Searcher = New-Object System.DirectoryServices.DirectorySearcher($DirectoryEntry)
$Searcher.Filter = "(sAMAccountName=$SearchUser)"
# Specify properties to load
[void]$Searcher.PropertiesToLoad.AddRange(@("displayName", "mail", "userPrincipalName", "distinguishedName"))
$Result = $Searcher.FindOne()
if ($Result) {
[PSCustomObject]@{
SamAccountName = $SearchUser
DisplayName = $Result.Properties["displayname"][0]
UserPrincipalName = $Result.Properties["userprincipalname"][0]
Email = $Result.Properties["mail"][0]
DistinguishedName = $Result.Properties["distinguishedname"][0]
} | Format-List
} else {
Write-Warning "User '$SearchUser' not found."
}
}
catch {
Write-Error "LDAP Search Failed: $_"
}