Results 1 to 2 of 2

Thread: One-way trust and user lookups

  1. #1
    Join Date
    Aug 2011
    Posts
    1

    One-way trust and user lookups

    To explain the issue in brief manner:
    I have 3 domain controllers, each one hosting different domain in their respective forests - calling them X, Y, Z

    X DC is Win 2003 R2
    Other 2 are Win 2008 server

    Created 2 trust relations, each one being one-way, external outgoing trust from X to Y and X to Z

    Configured my Samba server against the X domain controller.
    ----------------------------------------------
    So far so good.
    I have 2 client machines - Win XP and Win 7

    1. Win 7 client - Joined to Z domain
    If I logon as Z domain admin or any other user and try to add more users to access the samba share, in the 'Locations' button of 'security tab', if I try to 'find user' from Y domain, it asks for credentials of that domain.
    However it allows to 'find users' from the X domain without credentials for X domain

    2. Win XP - Joined to Y domain
    If I logon as Y domain administrator and try to add more user, the 'Locations' buttons allows me to 'find users' from both X and Z domain as well, without asking password
    Login from any other user from Y domain (not admin), it allows me 'find users' from X domain but for the Z domain, it asks credentials for Admin
    ---------------------------------------------------------------------------
    So, this has really confused me and I would like to understand how this works.
    I am using same samba share to connect from both client(connecting to clients through remote desktop)

    Is there some config that is missing on my Samba server or is it purely how my Widows client and the AD server interact ?

    Why is there difference between Win XP and Win 7 behaviour and then Admin user and any other user ?

    I was expecting that any user(admin or not) from Y and Z domain would not be able to 'find users' from each other domain without creds.
    Moreover, even the X domain users 'find users' would not work if my client is part of Y or Z domain

  2. #2
    Join Date
    Apr 2010
    Posts
    57

    Re: One-way trust and user lookups

    According to your description it seems to be the performance of Windows clinet PC's and I don’t believe whatever thing to be complete on Samba Server part. Secondly at what time you are creating trust at that moment someone is able to browse the users are happening you’re on top of. And why is it asking recommendation for Windows 7 PC is as under the trust is created among x to y and x to Z. The windows 7 PC is within Z domain and you are demanding to access resources commencing Y domain. There is no straight Trust among Y and Z domain.

Similar Threads

  1. Do you trust Ebay, if so, then how often do you use it ?
    By Kingston-Guy in forum Polls & Voting
    Replies: 8
    Last Post: 14-08-2012, 12:51 PM
  2. Replies: 5
    Last Post: 11-08-2010, 12:30 PM
  3. What are trust anchors in dns server
    By Raulf in forum Technology & Internet
    Replies: 5
    Last Post: 08-02-2010, 08:24 AM
  4. Replies: 0
    Last Post: 07-01-2009, 09:18 PM
  5. Force update of reverse lookups on AD DNS?
    By WarRen! in forum Window 2000 Help
    Replies: 1
    Last Post: 31-07-2006, 10:33 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,565,167.87046 seconds with 17 queries