In a cross-forest trust, a Windows Server 2003 CA will not by default chase, or attempt to find, user information necessary to approve a certificate request from a trusted forest. This constraint improves performance and also security because you might not want to issue certificates directly to users in the trusted forest. Cross-forest referral, or referral chasing, can be enabled via a certutil command on the CA. The certutil setreg policy +EDITF_ENABLELDAPREFERRALS command must be issued at the command prompt on the CA, and then the service must be stopped and started.

 

An enrollment agent can be restricted. Enrollment agents by default have sweeping powers and are able to issue certificates for anyone in the organization. Certificates can be restricted by permissions set on the certificate templates; however, for stricter control, the ability of the enrollment agent to issue certificates can be constrained by identifying both who can perform the enrollment and who an enrollment agent can enroll. To implement these additional restrictions, version 2 certificates are required.

 

When a user authenticates across a trust with the Selective authentication option enabled, an Other Organization security ID (SID) is added to the user's authorization data. The presence of this SID prompts a check on the resource domain to ensure that the user is allowed to authenticate to the particular service. Once the user is authenticated, if the Other  Organization SID is not already present, the server to which the user authenticates adds the This Organization SID. Only one of these special SIDs can be present in an authenticated user's context.

 

 

Requirements To create a realm trust, you must have Enterprise Admin or Domain Admin privileges for the domain in the Windows Server 2003 forest and the appropriate administrative privileges in the target Kerberos realm.

 

 

 

Rate this Article:
  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5
0 / 5 stars - 0 vote(s)
Add new Comment
Your Name *
Your Email: *
Your Comments: *
Enter Validation Code: * Captcha