• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 195
  • Last Modified:

Extending file services to another forest / domain users

There is a need to share AD objects, primarily files residing on an AD integrated NAS box, to our users on the Internet, and also to another set of users from one of our JV company's that runs it's own Windows 2003 Std. infrastructure. Ours is native Windows 2003 R2.

I want to avoid establishing trust between the two forests just for the sake of sharing files across which is currently accomplished by FTP transfers. What are my aternatives?
0
fahim
Asked:
fahim
  • 3
  • 2
1 Solution
 
LauraEHunterMVPCommented:
Sharepoint with AD FS for federated authentication.  Non-trivial to deploy, but it negates the need for an Active Directory trust or for VPN connecitivity between offices.

http://support.microsoft.com/default.aspx/kb/912492
http://blogs.technet.com/adfs_documentation/archive/2007/02/16/adfs-sharepoint-server-2007-new-content-available.aspx
0
 
fahimAuthor Commented:
Laura, having taken some time to read the stuff, I am a bit wary of two aspects:

1. It seems like AD FS needs to be deployed on both the forests and it rings about schema changes within AD. This is critical as I might not be able to convince our associated partners of undertaking this 'bit' risky operation on their current operational AD org.

2. AD FS over sharepoint is only available as a web interface over IIS. That means, I use browser for tranferring/sharing my files even after I deploy AD FS. Is there any other  (non browser) alternative?

You mentioned that AD FS is 'non trivial' to deploy. Pls elaborate a bit more on this aspect. Does non trivial also imply 'risky'?
Thanks!!
0
 
LauraEHunterMVPCommented:
1. AD FS does not require schema extensions.

2. AD FS provides web functionality only in its current release, this may change in future releases but nothing has been definitively announced.

3. Non-trivial only implies 'risky' if you do not test before you deploy; this applies to AD FS as much as any technology.
0
 
fahimAuthor Commented:
Laura one last point...should I presume 'yes' to my earlier query that I would need to enable ADFS on both the forests, 'to and from' I need to share AD objects/documents!!!??
0
 
fahimAuthor Commented:
Calling Laura...!!

Laura...Do I need to enable ADFS on both the forests across which I need to share my files/folders? Pls reply!
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now