Mark,
There
are a number of reasons as to why two domains with a trust between would not be
a secure method:
1. Domains in a forest are not truly secure elements in many
ways. Because an administrator in a domain has access to anything in his
domain, access to information in a GC or Configuration container is open, and
can potentially be compromised with a variety of attacks.
2. By default, there is a trust between domains in a forest - they
are automatically created and are transitive in nature. Given what
Ninet is after, this would not be acceptable as it's not really addressing the
larger problems.
Rick Kingslan MCSE, MCSA, MCT
|
Title: Message
- [ActiveDir] AD & DMZ's Ninet Segar
- RE: [ActiveDir] AD & DMZ's Rick Kingslan
- RE: [ActiveDir] AD & DMZ's jim . katoe
- Re: [ActiveDir] AD & DMZ's jim . katoe
- FW: [ActiveDir] AD & DMZ's Mark Kelsay
- RE: [ActiveDir] AD & DMZ's Rick Kingslan
- RE: [ActiveDir] AD & DMZ's Mark Kelsay
- RE: [ActiveDir] AD & DMZ's Byrne, Steve
- RE: [ActiveDir] AD & DMZ's Roger Seielstad