AD Transitive Trust Relationship
I'm tryign to establish a transitive Trust between two forest but it only ceatenon-transitive trust. How do I do that?
July 20th, 2010 5:49pm
More than likely you are not on a supported Forest Function level.
Creating Forest Trusts:
http://technet.microsoft.com/en-us/library/cc776940(WS.10).aspxVisit: anITKB.com, an IT Knowledge Base.
Free Windows Admin Tool Kit Click here and download it now
July 20th, 2010 6:47pm
Forest Trusts by definition are the equivalent of creating transitive trusts between every domain in each forest.
Read this for more information.
http://technet.microsoft.com/en-us/library/cc773010(WS.10).aspx
As far as i know, Forest Trusts themselves are not Transitive meaning Forests trusts betwen three forests (A->B->C) are not transitive. Thus A trusts B (->) but not C, because they are not transitive.
Since you only have 2 Forests this doesn't apply anyway.
July 20th, 2010 6:54pm
It's hard to say the cause as you need to provide some environment detials on what OS you're using.
Nontransitive trust
A nontransitive trust is restricted by the two domains in the trust relationship. It does not flow to any other domains in the forest. A nontransitive trust can be a two-way trust or a one-way trust. Nontransitive trusts are one-way by default, although
you can also create a two-way relationship by creating two one-way trusts.
In summary, nontransitive domain trusts are the only form of trust relationship that is possible between the following:
A Windows Server 2008 or a Windows Server 2008 R2 domain and a Windows NT domain
A Windows Server 2008 or a Windows Server 2008 R2 domain in one forest and a domain in another forest (when the forests are not joined by a forest trust)
AD Forest level transitive trusts aren't allowed (Forest A trusts Forest B & Forest B trusts Forest C, but Forest A & C trust isn't transitive as a result.)
Forest trust: A transitive trust between a forest root domain and a second forest root domain.
much of this is related that forests are the formal security boundary.
http://technet.microsoft.com/en-us/library/cc773178(WS.10).aspx
http://technet.microsoft.com/en-us/library/cc754612.aspx
Free Windows Admin Tool Kit Click here and download it now
July 20th, 2010 9:17pm
i'm runing Win2003 R2 and it has 2-way non-transitive trust relationship.The problem is that i can't login acorss the to domain but at the same time i can access the files. This what non-transitive designed for.
The documentation says I've make some DNS changes which I'm reluctant to do in the live/production environment unless i'm not sure.
July 21st, 2010 7:47pm
"If there is no shared root DNS server and the root DNS servers for each forest DNS namespace are running a member of the Windows Server 2003 family, configure DNS conditional forwarders in each DNS namespace to route queries for names in the other
namespace. "
since both the Forest has their own DNS server, do i need to create the condition fwding on both of these. let say domain A ea.local and domain b is ns.local , then what do i need to do in DNS?
Free Windows Admin Tool Kit Click here and download it now
July 21st, 2010 7:52pm
I've setup the forwarder and I can Ping the computer across both the forest. what else?
July 21st, 2010 7:59pm
Read up on the basic implentation for domain trusts.
http://technet.microsoft.com/en-us/library/cc776940(WS.10).aspx
Free Windows Admin Tool Kit Click here and download it now
July 27th, 2010 4:51pm