Re: Trusts without a direct connection between domain controllers?

From: GeeB (Geeb_at_newsgroup.nospam)
Date: 06/28/05


Date: Mon, 27 Jun 2005 18:33:27 -0400

I have a similar setup and our take for security reasons is not to even
attempt to have a trust between the two zones. All boxes in the secure zone
are handled by using Terminal Services to logon to the DC and manage the
domain from within the zone itself.
Other options:
- Windows Server 2003 Forest trusts
- Third-party tool that can manage any domain in any area regardless of any
trust or lack of it such as Quest or Bindview.

Interesting read:
http://www.microsoft.com/downloads/details.aspx?familyid=a97ddc48-a364-4756-bb3c-91da274118fe&displaylang=en



Relevant Pages

  • Re: Very Critical issue
    ... Since that you're able to recreate the trust that means that the DC that was used to create the trust is able to communicate and validate the trust. ... are the clients using that same DC/DNS or are they querying a different DC/DNS that may has issues in their DNS secondary Zone? ... was at that time that the clients started with issues when trying to access to the other servers in the other forest? ...
    (microsoft.public.windows.server.active_directory)
  • DANGER ZONE: Internet Explorer
    ... This may be achieved with the Internet Explorer series of so- ... and trust, ... The so-called "Trusted Site" zone setting in the Internet Explorer ... For example, we input into the so-called Trusted Zone, the ...
    (NT-Bugtraq)
  • DANGER ZONE: Internet Explorer
    ... This may be achieved with the Internet Explorer series of so- ... and trust, ... The so-called "Trusted Site" zone setting in the Internet Explorer ... For example, we input into the so-called Trusted Zone, the ...
    (Bugtraq)
  • [Full-Disclosure] DANGER ZONE: Internet Explorer
    ... This may be achieved with the Internet Explorer series of so- ... and trust, ... The so-called "Trusted Site" zone setting in the Internet Explorer ... For example, we input into the so-called Trusted Zone, the ...
    (Full-Disclosure)
  • Re: One Way Trust
    ... The secondary forward look up zone has been created on ... production domain has several domain controllers and I ... a outgoing one way external trust. ...
    (microsoft.public.windows.server.active_directory)