Trust through a RODC


we have windows 2003 domain prepared rodc. 1 dc win2008r2sp1, others win2003.

we need establish trust external organization (win2003 domain).

to protect ourselves want let partner access rodc install in dmz purpose.

to limit partner access other dcs want supply them dns zone contain srv records pointing rodc. created dns zone on dedicated dns server contains all srv records normal rw dc (not pdce) would register , pointed them rodc , supplied this dedicated dns ip to partner organization.

will work?

i know, need pdce establish trust, need afterwards?

do need direct contact pdce renew trust password?

do need direct contact rw dc renew trust password? or can rodc proxy requests them?

 

hi.
no scenario won’t work several reasons – rodcs can’t perform
cross-domain authentication without issuing referral rwdc @ both
ends (rodcs doesn't have knowledge of trust password).
 
please see: how cross-domain authentication process works rodcs:
http://technet.microsoft.com/en-us/library/cc754218(ws.10).aspx#bkmk_xdomauthn
 
 
----------------------------------------------------------
regards
christoffer andersson – principal advisor
enfo zipper
 
"i.a" wrote in message news:50f55866-7ab8-4cce-b07b-4c3b7696f4df...
 
we have windows 2003 domain prepared rodc. 1 dc win2008r2sp1,
others win2003.
 
we need establish trust external organization (win2003 domain).
 
to protect ourselves want let partner access rodc
will install in dmz purpose.
 
to limit partner access other dcs want supply them dns zone
will contain srv records pointing rodc. created dns zone on
dedicated dns server contains srv records normal rw dc (not
a pdce) register , pointed them rodc , supplied
dedicated dns ip partner organization.
 
will work?
 
i know, need pdce establish trust, need afterwards?
 
do need direct contact pdce renew trust password?
 
do need direct contact rw dc renew trust password? or can rodc
proxy requests them?
 
 
 
 

enfo zipper christoffer andersson – principal advisor


Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client