Solved

Looking for answers on  Two Way Trust Vulnerabilities

Posted on 2009-07-02
6
290 Views
Last Modified: 2012-05-07
I'm trying to put together a point paper explaining the benefits and the vulnerabilities of establishing a two way trust between two domains.  I've got plenty of information on the benefits but honestly I can't find anything "negative" towards establishing one.  Can anyone explain some of the inherent vulnerabilities of establishing a trust?  Users from domain A cannot access resources from domain B unless the permissions allow the specific user, authenticated users or everyone to access that resource.  Administrators from domain A should not be able to do any administration in domain B.  
The next question, what are some of the things I should do security wise to "protect" my network more once I establish a two way trust?
0
Comment
Question by:tej071
  • 3
  • 2
6 Comments
 
LVL 19

Expert Comment

by:deroode
Comment Utility
The name "Trust" says it all.

The admin of Domain B will have to trust the domain admins of domain A. In practice, permissions aren't assigned to specific users but to groups. If a domain admin A adds member "criminal" to a group which has full rights in "financial data" on domain B that is not visible.
0
 
LVL 1

Author Comment

by:tej071
Comment Utility
deroode,
Are you sure about the admins from one domain having rights on the other domain?  I ask this because an administrator in a child domain does not have rights to make changes to a parent domain and that is a transitive trust.  I understand users will have access to resources on the other domain but only if that is specifically set, they just dont' get access to resources just because a trust was established.
0
 
LVL 19

Expert Comment

by:deroode
Comment Utility
No, that was not wat i said.

If Domain admin B gives folder permissions to  a group from Domain A, he cannot see who is in the Domain A Group. The Domain admin from domain A however can put anyone from Domain A in that group.

Domain admin B cannot see that Domain admin A has added someone to the group, to him it's just the same group.
0
 
LVL 1

Author Comment

by:tej071
Comment Utility
Correct, I misread your original statement and the same is true WITHIN Domain A when I assign users to a resource with full rights from Domain A to resources in Domain A I trust that they won't cause trouble there as well.  
I guess my question was more geared toward Administrators from one domain being able to influence things in another domain once the trust is established.  Without assigning them any special rights they have no more abilities to make changes in my domain than a user on my domain has rights (i.e. adding user accounts, changing FSMO roles, changing SMTP connectors, etc), correct?

0
 
LVL 19

Accepted Solution

by:
deroode earned 500 total points
Comment Utility
Yes, that is correct.

I cannot help you with your second (security) question, sorry..
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

by Batuhan Cetin In this article I will be guiding through the process of removing a failed DC metadata from Active Directory (hereafter, AD) using the ntdsutil tool in a Windows Server 2003 environment. These steps are not necessary in a Win…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now