Jump to content

Recommended Posts

Posted

Hi all

I'm after a bit of guidance.

I want to set up a trust between our Admin and Pass servers.

Is it very difficult? Could someone give me a bit of advice or point me in the direction of a good manual?

We had a trust set up in my last school but I didn't have any involvement in that. It was already there.

Thanks

Posted
I'm slightly confused, are we talking about trusts between domains in different forests here, or is there some sort of trust you can set up between individual servers?
Posted
It's a trust between 2 servers on different domains. Not in different countries or parts of the country but standing next to each other. Users on one domain need access to certain parts of the other.
Posted
It's a trust between 2 servers on different domains. Not in different countries or parts of the country but standing next to each other. Users on one domain need access to certain parts of the other.

 

You will have to trust the whole domain not just one server. I have done it myself and its pretty easy. Are the Domains on the same LAN?

Posted

As FN says, it is fairly easy but it does have to be trust of the whole domain.

 

Or rather you have to set up a domain trust, then you can choose which assets from the foreign domain are trusted to access which resources, almost in the same way as you would with your own users.

Posted (edited)

The info provided only mentions server 2000 and server 2003. Our trust would be between a server 2003 and server 2008

 

Basically we need to be able to access SIMS which is on our admin network for the VLE and parental engagement, registration and the like. Our new server will be 2008, the admin one is 2003.

Will the 2003 instructions work for both?

Edited by witch
Posted
Mine are 2000 for the admin network and 2003 for the curriculum. Hopefully later this year they will both be 2003. A bit behind the times here.
Posted
I do believe if you right click your domains in Active Directory Users and Computers (or Domains and Trusts) you can choose a "Domain Functional Level" from the menu and that should tell you.
Posted

Chances are if you don't know the domain level, it'll be the default which is '2000 Mixed'. Setting up trusts are fairly straight forward, but in the longterm I would look at merging the admin domain (typically very small) with the curriculum domain.

 

With NTFS permissions and security groups, locking down shares is straight forward. It's not like the Windows 9x days where security was more of an issue. The other advantage (in my experience) is less administrative time involved. Only one Sophos AV and WSUS setup required instead of two (one for each domain).

Posted
Chances are if you don't know the domain level, it'll be the default which is '2000 Mixed'. Setting up trusts are fairly straight forward, but in the longterm I would look at merging the admin domain (typically very small) with the curriculum domain.

 

With NTFS permissions and security groups, locking down shares is straight forward. It's not like the Windows 9x days where security was more of an issue. The other advantage (in my experience) is less administrative time involved. Only one Sophos AV and WSUS setup required instead of two (one for each domain).

 

setting up the trust is easy if you have admin access to both domains and the networks are in some way connected.

 

id love to merge the networks but there are certain admin progs that have to be run on a x.x.even.100 whereas curric is x.x.odd.x so certain stuff would fail and in most of the schools i support i ONLY do curriculum (well in theory most admin support contracts (leeds atm is a joke for this) are pants and i end up doing everything but sims) i have one school where the lea's isp have installed a sisko (arrrggghhhhh) wireless setup (needs a gpo applied and a certificate ffs its a primary school not a bank) and the head keeps on at me to put her laptop on it (i had no involvement in the setup i just know how to connect domain pcs). That school also intend to run sims on curric pcs from september via a trust it does work as ive done it elsewhere (just badly as the lea set up sisko router between the networks only allows the top 32 ips to see the admin network) so i have to find the mac address of all the staff laptops and install sims via a trust (though i think ill just create a script to copy the sims inst dir to my server) that atm is only one way (to curriculum) and i have no access to admin fun aint it

 

as to sophos id rather have no av it would fix as many problems and wouldnt cripple pcs performance lol

Posted
Chances are if you don't know the domain level, it'll be the default which is '2000 Mixed'. Setting up trusts are fairly straight forward, but in the longterm I would look at merging the admin domain (typically very small) with the curriculum domain.

 

Why would you look at merging the domains in the long term? If the trust works, then what advantages would one domain have?

Currently we have two networks- I am completely responsible for the curriculum but have no involvement whatsoever with the admin,(done by the LEA) but the new govt rules require the teachers and vle to have access to sims so we have to do something.

I would like to merge the domains as it just seems right to me but I need big arguments to convince the powers that be!

Posted
Why would you look at merging the domains in the long term? If the trust works, then what advantages would one domain have?

Currently we have two networks- I am completely responsible for the curriculum but have no involvement whatsoever with the admin,(done by the LEA) but the new govt rules require the teachers and vle to have access to sims so we have to do something.

I would like to merge the domains as it just seems right to me but I need big arguments to convince the powers that be!

 

To minimise the administrative overhead of having multiple domains in separate forests. Separate domains are now no more secure than well-planned Active Directory partitioning and NTFS permissions, and of course well-defined and enforced human policies too, and Microsoft's official advice (at least last time I looked) has changed from 'keep them separate' to 'keep them simple'.

Posted

Yes, but the administrative overhead doesn't really apply as Dorset support the admin network completely, so in fact one network would mean more admin overhead for me - more servers, more computers to support etc etc.

Dorset LEA have been dragged kicking and screaming into the 21st century, finally, and will now 'allow' trusts to be set up but they still will not support the admin machines, SIMS or any financial packages if we go whole-school network.

So I guess I don't have a choice ATM.

I still don't understand quite how to set up a trust and I would be very wary of trying to sort out who can see what on my own. Any more advice, docs etc? gratefully received

Posted
Currently we have two networks- I am completely responsible for the curriculum but have no involvement whatsoever with the admin,(done by the LEA) but the new govt rules require the teachers and vle to have access to sims so we have to do something.

I would like to merge the domains as it just seems right to me but I need big arguments to convince the powers that be!

 

Merging the domains would be a simpler, easier option however a trust should work.

 

You'll need at least a one-way trust from your curriculum network to your admin network. That'll then let you authenticate users from the admin for access to resources on your curriculum network. You will need to speak to the LEA though and get them to set up the other end of the trust.

 

This is assuming that the VLE is on your curriculum network, and authenticates against AD.

Posted
I still don't understand quite how to set up a trust and I would be very wary of trying to sort out who can see what on my own. Any more advice, docs etc? gratefully received

 

I'm with Witch in this one. Any advice or pointers would be appreciated. People keep saying it's simple but not saying how.

Posted (edited)

Once the trust is set up you can apply restrictions as you normally would to users on your system, permissions and so on.

 

Note though, a domain is the boundary for account and policy settings, so GPOs which contain those settings won't affect the users when they log on to your computers.

 

To set up the trust is fairly simple, depending on the type you want. The difficult bit is remembering how trusts 'point'.

 

If Domain A trusts Domain B with an outgoing 1-way trust, then it means that users from Domain B can be recognised to access resources on Domain A.

 

If Domain A and Domain B trust each other with a two-way trust, users from both can access resources on the other.

 

Several links on trusts (may have already been posted):

 

Domain Trust - Explanation of domain trusts and considerations to remember when applying them.

 

How to Create a Trust Relationship from One Computer - step by step for setting up a trust for access to a single computer

 

Domain and Forest Trust Tools and Settings: Domain and Forest Trusts - details of the various tools related to Domain and Forest trusts

 

Create an external trust: Active Directory - creating a one-way outgoing/incoming external domain trust

 

Create a two-way, external trust for both sides of the trust: Domain and Forest Trusts - creating a two-way external domain trust

 

Create a one-way, outgoing, forest trust for both sides of the trust: Domain and Forest Trusts - creating a one-way external forest trust

 

Trust between a Windows NT domain and an Active Directory domain cannot be established or it does not work as expected - a common problem once the trust is established

 

Hope this helps.

 

Edit: If you set up a transitive trust then any child domains will also trust the trusted domain.

Edited by jamesb
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...