Re: Synchronizing Domain Users Passwords in Non-Trusted Domains

Tech-Archive recommends: Speed Up your PC by fixing your registry



Thanks for the replies. That is what I thought, but we are trying to do some
custom certificates and having a real tough time getting it to work. The
major problem on why we can't build a trust relationship is that one domain
is government and the other is county. Our easiest solution would be just to
make all those users members of the government side and take control of the
whole site like rest of the sites, but that is a power struggle and political.

What we are doing now, is we have a login script that some users click on
and then they have to login using their password, but when they change their
passwords we have to manually change them as well.

"Joe Kaplan" wrote:

This is a good job for MIIS. Account sync between non-related domains is
not a feature that is supported by AD natively.

A federation solution may be useful, but would require more creativity and
might require provisioning of matching shadow accounts in the other domain,
so there is still a provisioning component that is implied.

Joe K.

--
Joe Kaplan-MS MVP Directory Services Programming
Co-author of "The .NET Developer's Guide to Directory Services Programming"
http://www.directoryprogramming.net
--
"Ryan Hanisco" <RyanHanisco@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:91FF0DB7-028F-429A-B065-5EA6BCC63EF6@xxxxxxxxxxxxxxxx
Hi Andy,

Without a trust in place, there isn't really a way for the Database in
another domain to get at the credentials. You could either do something
based on database credentials or even something with certificates, though
you
would need to trust the foreign CA and do custom work on the
authentication.

Without working for it, I'd say you are probably best to look at the
business need vs. the other domain's insistence that there cannot be a
trust.
Outside of that your options might be to look at ADAM or Federation
Services
to extend authentication outward.

In any case, I don't see an easy path. Any one else???
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
http://www.techsterity.com
Chicago, IL

Remember: Marking helpful answers helps everyone find the info they need
quickly.


"Andy" wrote:

We are working with users that are a member of Domain A that need to be
able
to communicate to their database in Domain B. Domain A server resides on
location along with their DC. Domain B will have the database that also
resides on location, but the DC is off site.

The problem is that we cannot setup a trust delegation since the Domain B
will not allow us to build one. So, is there a way to be able to allow
users
on Domain A to still be able to get to the database even after their
passwords change and still be able to sync to Domain B either through a
certifcate or script of some sort?

Any light on this would be great. BTW, both domains are using Win2k3
servers and XP machines. There are no SQL servers on either location,
but
we are using Oracle for the main database.



.



Relevant Pages

  • Proofs, burdens, abrahamic claims, and out-of-band data
    ... When you get a trust point certificates so you can tell if the site ... method that does not directly involve in-band transmission. ... The usual way to do out-of-band is to have the manufacturer of your ...
    (soc.religion.mormon)
  • Re: New Method for Authenticated Public Key Exchange without Digital Certificates
    ... > certificates were redundant and superfluous when the relying party ... > context of the original posting) and the semantic meaning of trust ... > the addition of public key operations to these environments isn't to ... > operations are the financial institutions. ...
    (sci.crypt)
  • Re: Proposal for a new PKI model (At least I hope its new)
    ... >>If we should trust these certificates, ... (Just as we should do for existing certificates issued by ... > level certificate to a small organization's PKI server in australia ... HTTPS is precisely so I don't need to trust DNS: ...
    (sci.crypt)
  • Re: Listbox Row Selection - Problems Passing Values
    ... Oddly, if I use ListBox.Requery in the AfterUpdate event, just before I pass ... Trust the folder where the database resides. ...
    (microsoft.public.access.formscoding)
  • Re: NSA wiretap, Friday night
    ... we know that they're going to spy on us, or at least someone is going to ... Move to a backwards country that has a lack of technology. ... this generations introduction to The Database most ... other private information if you happen to trust me more than any ...
    (comp.os.linux.security)