Solved

Establish one-way external outgoing trust using RODC in trusted domain jh

Posted on 2011-09-15
6
1,456 Views
Last Modified: 2012-05-12
We have a domain that we'll call 'resource' that needs to be accessed by users in a third party domain that we'll call 'source.'

Due to security issues, we cannot route to all of the domain controllers in source from resource. What we've done is setup a DMZ in source and placed a RODC in it. We've created a dns zone on the DNS servers in resource pointing to the RODC (so all the necessary _ldap and _kerberos SRV records and the necessary A records).

When we try and create the external outgoing trust, we receive a message saying: 'The name you specified is not a valid Windows domain. Is the specified name a Kerberos V5 realm?'.

I've been told that the source RODC has full access to the writeable DCs in its domain. I'm also told that we should be able to setup the trust using the RODC, although I am sceptical.
0
Comment
Question by:tlcsupport
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
6 Comments
 
LVL 37

Expert Comment

by:Neil Russell
ID: 36541911
On your Source domain you need to have a DNS forwarder set up pointing to any valid DNS server on Resource, the RODC? Have you done this?
0
 
LVL 1

Author Comment

by:tlcsupport
ID: 36542108
Yes, the source domain has a conditional forward to the resource domain and we have confirmed that queries resolve correctly.
0
 

Expert Comment

by:CiboZe
ID: 37507522
Hello tlcsupport,

I am curious if you have been able to set up this trust using the RODC.? I am considering a similar trust setup and can not find any documentation certifying a RODC can be use this way.

0
DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

 
LVL 1

Accepted Solution

by:
tlcsupport earned 0 total points
ID: 37507574
We ended up setting up the trust with a writeable DC, then replaced it with a RODC later and fudged DNS at the trusting end to only see the RODC at the trusted end.
0
 

Expert Comment

by:CiboZe
ID: 37509074
Thank you very much for the feed back.
0
 
LVL 1

Author Closing Comment

by:tlcsupport
ID: 37545708
Appears to not be possible. Although it's possible to setup the trust with a writeable DC at the trusted end and then replace with a RODC later.
0

Featured Post

Business Impact of IT Communications

What are the business impacts of how well businesses communicate during an IT incident? Targeting, speed, and transparency all matter. Find out more in this infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question