LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-24-2015, 12:54 PM   #1
watcher69b
Member
 
Registered: Nov 2007
Location: /home/watcher69b
Distribution: RH, Fedora & CentOS
Posts: 552

Rep: Reputation: 41
Winbind AD and Domain Trusts


I have a few CentOS boxes joined to the AD domain with winbind.

If I establish a trust with a DMZ domain would systems joined to the DMZ domain be able to access the internal domain via the Microsoft domain trust?

Anything else I should consider?


Thanks!
 
Old 03-25-2015, 08:59 PM   #2
dijetlo
Senior Member
 
Registered: Jan 2009
Location: RHELtopia....
Distribution: Solaris 11.2/Slackware/RHEL/
Posts: 1,491
Blog Entries: 2

Rep: Reputation: Disabled
Are both domains part of the same kerberos realm? ( I noticed you're using krb in your previous script, thanks again BTW)
Are you trying to create a two way trust? It's been awhile since I had win servers to deal with but I seem to remember you can set up different trust relationships between domains.
 
Old 03-26-2015, 07:12 AM   #3
watcher69b
Member
 
Registered: Nov 2007
Location: /home/watcher69b
Distribution: RH, Fedora & CentOS
Posts: 552

Original Poster
Rep: Reputation: 41
No, I believe they are seperate KRB domains. Our DMZ, we can call it BOBNET.INT, has a one way trust where it can read from BOB.INT.

There are no users/groups in the DMZ (BOBNET.INT) domain only computer accounts.

When I have setup AD auth in the past normally the server and the users all are located in the same (BOB.INT) domain.

Currently I am setting up AD auth for a server in the DMZ (BOBNET.INT) but don't know if I should do anything special or different so that AD auth will work
 
Old 03-26-2015, 08:03 AM   #4
dijetlo
Senior Member
 
Registered: Jan 2009
Location: RHELtopia....
Distribution: Solaris 11.2/Slackware/RHEL/
Posts: 1,491
Blog Entries: 2

Rep: Reputation: Disabled
You probably have a trust relationship between realms, the systems create a map of domain names -> realms and query DNS for the local service record and then sift the table to find the relationship based on domain name. That trust relationship has to be set up, though if I recall that's done on the KDC and not the local client. (Thanks God for the Manual)
Quote:
There are no users/groups in the DMZ (BOBNET.INT) domain only computer accounts.
They have to have local accounts then, otherwise how would you log into them? The way you're explaining the one way trust makes sense, if the two domains were fully trusted, then users from BOB would be able to log onto machines in BOBNET using their BOB domain accounts since the security database would be replicated.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Able to authenticate to Domain Alias using Winbind? theace18 Linux - Server 0 06-26-2013 07:45 PM
Samba Winbind and 2003 domain carnold SUSE / openSUSE 0 08-26-2005 05:53 PM
Auth in a NT domain using Squid and Winbind grbbarros Linux - Networking 0 02-19-2004 08:54 AM
Samba + Winbind + Domain Users group wheeliemonster Linux - Networking 0 01-27-2004 09:56 AM
authenticating windows domain users using winbind kidd Linux - Networking 2 09-24-2003 02:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 02:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration