[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


Single label domain names

Posted on 2006-04-26
Medium Priority
Last Modified: 2008-02-20
I have three single-label domains.  By single lable, I mean my domains names are simply domain1, domain2 and domain3.  There is not .com or anything like that.

Anyway, I am trying to use the ADMT to migrate users from one domain to another and domain1 cannot see domain2 or domain3.

I am asking what I must do to my DNS in order for these three single lable domains to see each other?


Question by:crp0499
  • 3
  • 3

Expert Comment

ID: 16549004
Since there is not an FQDN I am assuming that this is a series of NT4 domains, you will want to create two way trusts to each of the domains (d1<->d2, d1<->d3, d2<->d3).  

This is done from the Domain User Manager Policies entry on the menu bar.
From the Policy menu, select Trust Relationships. Next to the lower box labeled Permitted to Trust this Domain are two buttons, Add and Remove. The Add button will open a panel in which to enter the name of the remote domain that will be able to assign access rights to users in your domain. You will also need to enter a password for this trust relationship, which the trusting domain will use when authenticating users from the trusted domain. The password needs to be typed twice (for standard confirmation).

To consummate the trust relationship, the administrator will launch the Domain User Manager from the menu select Policies, then select Trust Relationships, click on the Add button next to the box that is labeled Trusted Domains. A panel will open in which must be entered the name of the remote domain as well as the password assigned to that trust.  Ensure that there is a trust running in both directions.

You may need to update wins with the PDC information from the other domains on each.

That should do it

Author Comment

ID: 16549258
Sorry, these are three Server 2003 Enterprise domains.

Accepted Solution

lavazzza earned 2000 total points
ID: 16549451
Sorry, thrown off by the use of domain names., use Active Directory Domains and Trusts to set up 2 way trusts between the domains.  Set up secondary dns zones from each of the domains to one another, example
Domain 1 - trusts domain 2 and domain 3, secondary zones for domain 2 and domain 3
Domain 2 - trusts domain 1 and domain 3, secondary zones for domain 1 and domain 3
domain 3 - trusts domain 1 and domain 2, secondary zones for domain 1 and domain 3

You may have to set the dns search order.
Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.


Author Comment

ID: 16549487
Thought of that, but when I attempt to set up trusts, domain1 can't find domain2, etc.  Hence, I figure my DNS is wrong.  I've read at length about single-label domain names and the domain rename tool.  I'd like to leave it like it is as these three domains will not grow at all.

So, back to my original question...how to set up DNS to each single-label domain can see the other two single-label domains so that I then can establish trusts.


Expert Comment

ID: 16549863
set up a secondary zone for the other domains in each domain, in this scenario the primary or active directory integrated zone will be authoritative.  Allow zone transfers between the dns servers in each single label domain.

Author Comment

ID: 16552176
ok, I had set them up as primary zones.  I'll move them to secondary.

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
This may not be a text book method to resolve VSS backup issues but it seemed to have worked on few of the Windows 2003 servers we had issues while performing a Volume Shadow Copy backup. If you have issues while performing a shadow copy backup usin…
Are you ready to place your question in front of subject-matter experts for more timely responses? With the release of Priority Question, Premium Members, Team Accounts and Qualified Experts can now identify the emergent level of their issue, signal…
In a question here at Experts Exchange (https://www.experts-exchange.com/questions/29062564/Adobe-acrobat-reader-DC.html), a member asked how to create a signature in Adobe Acrobat Reader DC (the free Reader product, not the paid, full Acrobat produ…

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question