Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Establishing trust with NT4 domain

Status
Not open for further replies.

ianf

MIS
Mar 23, 2001
183
GB
Hi All,

I have the following problem.

I have a W2K Advanced Server installation without Active Directory (therefore it is standalone). My requirements have changed since I did the initial install. I need the standalone server to be able to establish trusts with a pre-existing NT4 domain. The server CANNOT become a member of the NT4 domain. The W2K server should trust certain users of the NT4 domain but the NT4 domain doesn't want to trust any W2K users.

This is sort of where I start waffling trying to sound like I know what I'm talking about;
I assume that the only way to acheive this is to install AD then run DCPromo. If there is an option of not installing AD and still being able to establish trusts, I'd like to know about it, as AD seems like overkill for one server.

Cheers Ian

"IF" is not a word it's a way of life
 
Depending on exactly what you want to do...you could synchronize the proper users accounts on each side.

For example, say you have six users in the domain:

billydomain\user1
billydomain\user2...user6

You can create these users accounts on the untrusted member server as well. Then, at least these specific users would be able to access the server without any problems..

Joseph L. Poandl
MCSE 2000

If your company is in need of experts to examine technical problems/solutions, please check out
 
Thanks Joseph,

That was my manual workaround, in place as we speak. It works but as the number of users grows from it's current 1, I'm going to run into problems keeping up with it by hand.

The aim of the game is not to require manual update of UID & PWD on the untrusted server everytime a new NT4 domain user needs resources from the W2K domain.

Ideally I want to create a single user group that all the users who log into the W2k server from outside, are members of. This group should be administered by the NT4 domain, but trusted by the W2K domain. Ian

"IF" is not a word it's a way of life
 
only way to do this properly is (I'm sorry) : run dcpromo and make a new Win2K DC
(don't choose the same Domain name as your NT4 domain...)

Then set up the trust and assign permissions... ---------------------------------------------------------------------
I have not failed, I've just found 10,000 ways that don't work
---------------------------------------------------------------------
Peter Van Eeckhoutte
peter.ve@pandora.be
*:->* Did this post help? Click below to let me know !
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top