Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Trust Relationships
2
What Are Trusts?
One-way incoming
incoming trust
trust
Trust
One-way outgoing trust
directions
Two-way trust
trust
Five types of
of trusts: Default, Shortcut,
Trust types
External, Forest and Realm
3
Trust Relationships in Windows Server 2003
Default
Two-way- transitive Kerberos trusts (Intraforest)
Shortcut
One or two-way transitive Kerberos trusts (Intraforest)
Reduce authentication requests
External
one way non-transitive NTLM trusts. Used to connect
to/from Windows NT or external 2000 domains
Manually created
Forest
One or two-way transitive Kerberos trusts. Only
between 2003 Forest Roots, Creates transitive domain
relationship
Realm
one or two-way non-transitive Kerberos trusts
Connect to/from UNIX Kerberos realms
4
ACTIVE DIRECTORY TRUST MODELS
Transitive Trust:
B trusts C then
A trusts C
NET.SOFT.COM MCSE.ZOOM.COM CCNA.ZOOM.COM
VB.NET.SOFT.COM
MCP.MCSE.ZOOM.COM
5
Default Trusts
SOFT.COM ZOOM.COM
Forest Root
VB.NET.SOFT.COM MCP.MCSE.ZOOM.COM
AA Default
Default trust:
trust:
Automatically
Automatically Created
Created
Transitive trust
trust
Two-way
Two-way transitive
transitive
6
Shortcut Trusts
SOFT.COM ZOOM.COM
Forest Root
Shortcut
Shortcut Trust
Trust Shortcut
Shortcut Trust
VB.NET.SOFT.COM MCP.MCSE.ZOOM.COM
A shortcut trust:
trust:
Reduces
Reduces authentication
authentication time
time in
in complex
complex forests
forests
Is
Is partially
partially transitive
transitive
Can
Can be
be one-way
one-way or
or two-way
two-way
7
External Trusts
Forest 1 Forest 2
ZOOM.COM IBM.COM
SOFT.COM
Forest Root
External
External Trust
Trust
An
An external
external trust
trust is:
is:
AA trust
trust that
that is
is manually
manually created
created between:
between:
Two
Two Active
Active Directory
Directory domains
domains located in different
different forests
forests
An
An Active
Active Directory
Directory domain
domain and
and a Windows
Windows NT
NT 4.0
4.0 or
or earlier
earlier domain
domain
Nontransitive
Nontransitive
One-way
One-way
8
Forest Trusts Forest
Forest Trust
Trust
Forest 1 Forest 2
ZOOM.COM IBM.COM
SOFT.COM
Forest Root Forest Root
JAVA.SOFT.COM
A forest trust
trust is a trust between two
two Windows Server 2003 forests
9
Realm Trusts
AA realm trust:
trust: ZOOM.COM
Is a trust
trust between
between aa
Kerberos realm
realm and
and an
an
Active
Active Directory
Directory MCSE.ZOOM.COM CCNA.ZOOM.COM
domain
domain
Can
Can bebe transitive
transitive or
or
nontransitive
nontransitive
Can
Can bebe one-way
one-way or two-
two- MCP.MCSE.ZOOM.COM Realm
Realm Trust
Trust
way
way
Kerberos Realm
10
11
Domain and Forest Functional Levels
12
Domain Functional Levels
Domain Controller
(Windows Server Domain Controller
2003) (Windows Server
2003)
13
Domain Functional Levels
14
Forest Functional Levels
15