Domain Trusts and LDAP

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: GMartin (gmartin_at_gmartin.org)
Date: 01/13/05


Date: Thu, 13 Jan 2005 09:57:19 -0500

We're building an AD infrastructure to authenticate users of our
external web via LDAP. We already use AD internally. We need a
mechanism to allow internal users to authenticate to the external system
without creating new credentials for them.

My idea is to create one-way trust from the external domain to the
internal domain. This should allow one-stop shopping for the
authentication (vs. LDAP referral and a hole in the firewall from the
app svr to the internal AD). I think this will work, but I have several
questions

1 - How do we authenticate? We typically do a search & bind to
authenticate against LDAP. If I understand correctly, the search would
not work as the external AD wouldn't search the internal. Would we use UPN?

2 - When we create an account externally, how can we ensure (dow e need
to ensure) the account is unique in both domains (I guess is we use UPN
this wouldn't matter)

Thought on these or other suggestion on approaching the problem?

\\Greg



Relevant Pages

  • Re: ipfw plus authentication (authpf is cool but....)
    ... their ipaddress, mac address, workstation os, etc. in our ldap directory. ... gain network access is indeed belongs to that user. ... router first before being allowed to access any server. ... user will authenticate to a web based login form which is tied up ...
    (freebsd-questions)
  • Re: Trouble Authenticating users from trusted domains
    ... For the internal referrals, ... We have a new ERP system that can either authenticate with it's own user ... If you specify an LDAP server, ... >> login as a user from the child domain, ...
    (microsoft.public.win2000.active_directory)
  • RE: Cant authenticate to LDAP domain with Redhat9
    ... it is more used by the authconfig ... sure you can reach your ldap server with ldapsearch, ... Cant authenticate to LDAP domain with Redhat9 ...
    (RedHat)
  • Re: Anonymous LDAP Access Problem
    ... Check the ADSI ... I need to authenticate using LDAP and I still am having some problems. ... which works when that is a domain account, but does not when that account ...
    (microsoft.public.windows.server.active_directory)
  • Re: Cant authenticate to LDAP domain with Redhat9
    ... >Subject: Re: Cant authenticate to LDAP domain with Redhat9 ... I wanted to check with my boss before messing with the ldap server. ... >If you still think I need to look at the ldap server log files I will. ...
    (RedHat)