Skip to content

Tristan Watkins on IT Infrastructure

Technical guidance for Microsoft security technologies, Windows, SharePoint, and other generally useful findings

Tag: Export

User Profile Picture and Certificate Trusts

In my post yesterday on User Profile Picture Export Permissions I reviewed the requirements to export the SharePoint PictureURL profile property to the Active Directory thumbnailPhoto user attribute. Where I left off, I had identified a certificate error on our SSL-secured MySite’s wildcard certificate. You may recall that the User Profile synchronisation exported the mobile number property successfully. Given that this mobile number was updated by the end-users though the same MySite host as the User Profile picture, you may wonder why one exported successfully if there were certificate errors that interfered with the other.

Fundamentally, it’s irrelevant that this data was updated by these users in their MySites. The property could have been updated by an administrator in the User Profile Service Application. However, it appears that the User Profile export is not just exporting the URL as a string, it is actually copying the image on export; the User Profile Service Application is browsing to the SSL-secured site to pick up the image and writes it to the user’s thumbnailPhoto attribute. In this post I’ll review the evidence and explain the additional certificate trust configuration required to export an SSL-secured User Profile picture.

Continue reading “User Profile Picture and Certificate Trusts”

Author Tristan WatkinsPosted on September 2, 2010Categories Security, SharePointTags Active Directory, certificates, Export, FIM, Picture, Service Applications, SSL, User Profile, web services19 Comments on User Profile Picture and Certificate Trusts

User Profile Picture Export Permissions

Most IT Professionals with SharePoint 2010 experience will be familiar with the initial configuration complexities of the User Profile Service Application but it’s probably less well-known that there are additional requirements to set up profile property export, and that some properties have further requirements still. SharePoint 2010 allows properties to either be imported or exported (but not both, out of the box). The most basic of these requirements for Active Directory export are the Write All Properties and Create Child Objects permissions on the OUs where data will be written by SharePoint.

We initially followed Matthew McDermott’s Profile Image Export suggestions but in our case these steps were insufficient, as detailed below. That article was written while SharePoint 2010 was a beta product. The User Profile Service Application changed since that release and is now configured differently, so it doesn’t surprise me that our experience differs.

You might wonder why we spent this much effort just to get a picture in Active Directory (of all places). While we think it’s important to have this knowledge for our clients and delegating photo selection to end users can drive SharePoint adoption, it is also used by the Outlook 2010 Social Connector. When you start using this great new social computing front-end, it just feels incomplete without a photo.
Continue reading “User Profile Picture Export Permissions”

Author Tristan WatkinsPosted on September 1, 2010Categories Security, SharePointTags Active Directory, certificates, Export, FIM, Picture, SQL, User Profile6 Comments on User Profile Picture Export Permissions

On Twitter

My Tweets

Recent Comments

  • Reduslim prezzo in farmacia on DCOM Security for SharePoint Administrators
  • Ye Zejun on No Lossless Audio With Zune
  • Tristan Watkins on Start using Claims X-Ray with Azure AD
  • Robin on Start using Claims X-Ray with Azure AD
  • Tristan Watkins on Product Version Job: DCOM 10016 strikes again

Categories

  • Administrivia (1)
  • Authentication (21)
  • Business Continuity (3)
  • Client applications (20)
  • Consultancy and Design (21)
  • Hardware (9)
  • IT Management (14)
  • Miscellaneous (5)
  • Mobile (4)
  • Networking (18)
  • Office 365 Grid (5)
  • Performance (26)
  • Power (2)
  • Security (35)
  • SharePoint (81)
  • Unified Communications (4)
  • Virtualisation (30)
  • Windows (62)

Tags

  • Active Directory
  • AD FS
  • administration
  • Amazon Web Services
  • ASUS
  • Azure AD
  • certificates
  • Claims
  • Cloud
  • DCOM
  • Dell
  • development
  • DNS
  • EC2
  • FIM
  • Graphics
  • Hyper-V
  • IaaS
  • ICS
  • IIS
  • Information Rights Management
  • Intel
  • IRM
  • LDAP
  • Lync
  • Office 365
  • PowerShell
  • RMS
  • SAML
  • Search
  • SharePoint
  • SharePoint 2007
  • SharePoint 2010
  • SLAT
  • SSL
  • Token
  • User Information
  • User Profile
  • Virtual Machine
  • VMWare
  • w3wp
  • Windows 7
  • Windows Deployment Services
  • Windows Server 2008 R2
  • Workgroup

Archives by Month

Tristan Watkins on IT Infrastructure Proudly powered by WordPress