Re: AzMan with 2000 mixed DC

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 04/30/05

  • Next message: Malke: "Re: how to restrict limited user only visiting several websites"
    Date: Fri, 29 Apr 2005 19:07:48 -0700
    
    

    First, I do not know.
    Second, I am guessing that would not work.

    One of the reasons W2k3 domain and forest funtional levels
    are required is to enable use of Kerberos constrained delegation.
    >From what I am hearing, you would have the AzMan app over in
    a different forest, and while identities flowing in over the trust
    from the now existing forest could be used in the web app, I am
    thinking there would be issues when you went to flow the credentials
    the roles has map to back over the trust.

    -- 
    Roger Abell
    Microsoft MVP (Windows  Security)
    MCSE (W2k3,W2k,Nt4)  MCDBA
    "richlm" <richlm@nospam.nospam> wrote in message
    news:e0w$S7%23SFHA.2996@TK2MSFTNGP15.phx.gbl...
    > We are deploying an application which uses AzMan, with the store in AD,
    and
    > have just discovered that it won't work with the production DC which is
    > Windows 2000 in "mixed" mode.
    >
    > For AzMan to work it has to be a Windows 2003 "native" mode which is not
    > possible as there are Unix machines in the domain.
    >
    > We need to preserve the windows authentication capabilities in AzMan,
    > against users and groups in the existing (windows 2000 mixed) domain.
    >
    > Would a separate Win2003 domain with trust relationship to the primary
    > domain be a solution? If so would users need to be replicated to the
    Win2003
    > DC?
    > Can anyone suggest other alternatives?
    >
    >
    

  • Next message: Malke: "Re: how to restrict limited user only visiting several websites"

    Relevant Pages

    • Re: Raising the Domain and Forest Mode
      ... See also this article because of different security settings between NT4 and 2003 trust. ... domain (Windows Server 2003 Domain Mode) and a Windows NT domain, ... What you can think about is using forest trust's instead of two-way. ... The functional levels of the domain/forest are ...
      (microsoft.public.windows.server.active_directory)
    • Re: Re: Re: Re: Gradually migrate from Win2000 to Win2003 AD
      ... > Thanks for the info. Windows 2003 is quite new to me so I will have to ... > NTFS is far more effective and adding share permissions only ... >> This is approximated by Forest level trusts. ... >> trust between the two forests to be transitive to all ...
      (microsoft.public.win2000.active_directory)
    • Re: Domain Functional Levels and Trusts
      ... > a Windows 2000 Mixed Mode domain? ... >>> I need to build a trust between two domains in separate forests. ... >>> Domain Functional Level. ... >> a pair of domains which are not in the same forest. ...
      (microsoft.public.windows.server.active_directory)
    • Re: AD trust RPC
      ... I have a two way transistive trust between two 2003 native mode ... DC1 is a DC in my forest, T1server2 is a DC in the other ... The session setup to the Windows NT or Windows 2000 Domain Controller ...
      (microsoft.public.windows.server.active_directory)
    • RE: pass-through authentication
      ... domain tree, and between trees in a forest, are transitive and ... but to all domains in the Windows 2000 ... But windows NT domains on your network, trust ...
      (microsoft.public.win2000.active_directory)