Endpoint Protection

 View Only
  • 1.  AD Synch

    Posted May 29, 2009 11:26 AM
    Is it possible to setup AD Synch to run at a particular time?
    I only see Auto-schedule or Synchronize every X hours.


  • 2.  RE: AD Synch

    Posted May 29, 2009 02:21 PM
    Nope, only those two options are avalible at the momemt.

    But go to ideas and put in that you what this and that, and why you what it. Then maybe if we are lucky they will implement it in a future version :-)




  • 3.  RE: AD Synch

    Posted May 29, 2009 02:44 PM
    When performing the AD sync, does anyone know if the AD password for a user is stored in the SEPM database encrypted? Furthermore, is a secure transmission used to sync the password between AD and the SEPM database or is it sync'd using clear text?


  • 4.  RE: AD Synch

    Posted May 29, 2009 03:01 PM
    Hi

    The SEPM DB is encrypted with the password to put in under the installation or if you choose the simple inst with the admin password.

    I think they are using a normal LDAP request, but are not sure. Haven't though of this until now.

    You are also using a AD user if your are using your LDAP structure as groups.

    But I can't imaging that they haven't this under control, if not. They should stop selling security products :-))


  • 5.  RE: AD Synch

    Posted Jun 01, 2009 03:07 PM
    If you look in the helpfile, it says "You can also edit the interval by editing the tomcat\etc\conf.properties file." Anyone know what these options would be?



  • 6.  RE: AD Synch

    Broadcom Employee
    Posted Jun 02, 2009 01:27 AM
    this could be scm.timer.activedirectory settings under conf.properties/


  • 7.  RE: AD Synch

    Posted Jun 12, 2009 01:07 PM
    Can someone from Symantec shed some light on this?
    Thanks


  • 8.  RE: AD Synch

    Posted Jun 12, 2009 01:28 PM

    What do you mean by perticular time?


  • 9.  RE: AD Synch

    Posted Jun 12, 2009 01:31 PM
    umm like 1 AM in the night?


  • 10.  RE: AD Synch

    Posted Jun 12, 2009 01:41 PM

    No soultion right now.

    But what you can do is if you really wnat that to run at 1 am you can delete  your AD from the SEPM & you can try to readd it at 1AM if possible.
    Because it will run the syncronization every 24 hours from the time it is configured.  :)

    You can put your add a request for Product Enhancement on this link

    http://engweb.symantec.com/enhancement/members/product_select.asp