Cross Domain Authentication - Active Directory

Cross Domain Authentication - Active Directory

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Cross Domain Authentication - Active Directory mn_ms_user 07-18-2006
Posted by =?Utf-8?B?bW5fbXNfdXNlcg==?= on July 18, 2006, 11:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I hope I am posting to the correct group -> appologies if not.

I have two AD domains, Domain A and Domain B with Domain B trusting Domain
A. When a server in Domain B is referenced by FQDN from a system in Domain A,
it prompts for a username, password and domain. If the server in Domain B is
referenced by NetBios name, the authentication is seamless. Users in Domain A
are part of a group in Domain B that has the necessary permissions setup on
the resource they are trying to access.

Any ideas why? Anyone know where I can find some documentation on this issue?

Thanks in advance.

Posted by Roger Abell [MVP] on July 18, 2006, 2:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You need to be more specific.
These are apparently in two separate forests, but what kind of trust is
defined ? Just a downlevel NT4 era one-way, which seems to be what
you have described.
Also, what kind of access is being attempted? IE browser to something,
\unc\path to some share, custom application, etc. etc.
The two domains apparently share a means for mutual name resolution
for both DNS and WINS.
It almost sounds as if the attempt via FQDN, which would expect to
use Kerberos does not "shift" to attempting pass-through like authN
with NTLM after it finds Kerberos fails on the downlevel trust.

>I hope I am posting to the correct group -> appologies if not.
>
> I have two AD domains, Domain A and Domain B with Domain B trusting Domain
> A. When a server in Domain B is referenced by FQDN from a system in Domain
> A,
> it prompts for a username, password and domain. If the server in Domain B
> is
> referenced by NetBios name, the authentication is seamless. Users in
> Domain A
> are part of a group in Domain B that has the necessary permissions setup
> on
> the resource they are trying to access.
>
> Any ideas why? Anyone know where I can find some documentation on this
> issue?
>
> Thanks in advance.



Similar ThreadsPosted
Active Directory Authentication over Firewalls January 31, 2006, 1:42 am
Looking for a proximity solution for Active Directory authentication April 27, 2006, 4:39 pm
IIS 6 w/ NT 4.0 and Active Directory Domain Accounts October 11, 2005, 1:16 pm
active directory August 24, 2005, 6:52 pm
Active Directory and DMZ February 11, 2008, 10:12 am
Need help on Active directory server August 12, 2005, 6:29 am
Active Directory and SSL Certificates January 11, 2006, 5:08 pm
dates in active directory February 20, 2008, 6:04 pm
Using IPSec with Active Directory authetication September 5, 2005, 2:52 am
User Rights In Active Directory January 11, 2006, 12:50 pm

The site map in XML format XML site map

Contact Us | Privacy Policy