OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: DCOM Authentication acrosss NT Domains?

From: Christof Stadler (christofstadlerCHRISTOFSTADLER.DE)
Date: Thu Mar 20 2003 - 13:26:10 CST


> Have a look at http://www.develop.com/kbrown/com/secfaq.htm if you
> haven't seen if before. It's a good first step.

I'll do so for sure!

> Remember that this is pretty closely related to the security where a
> user in one domain tries to access resources in another domain. The
> client must provide credentials that the target domain can trust. If
> the
> target domain has a cross-trust or a one-way trust then the client can
> provide his own credentials. Otherwise, the client must provide the
> credentials of an account in the target domain.
>
That was also my understanding. I really suspect that our customer has
not established the appropriate trusts between his domains, because
otherwise it should just work.

> It is very useful to turn on the logon/logoff auditing in both
> environments for tracking down problems like the one you are facing,
> using Event Viewer.
>
Cool! I didn't know that this feature exists, I'll give it a try.

Regards

Christof

----------------------------------------------------------------
Users Guide http://discuss.microsoft.com/archives/mailfaq.asp
contains important info. Save time, search the archives at
http://discuss.microsoft.com/archives/index.html .
To unsubscribe, mailto:DCOM-signoff-requestDISCUSS.MICROSOFT.COM