[cifs-protocol] Can an AD server have more than one domain?

Andrew Bartlett abartlet at samba.org
Wed May 20 07:02:36 GMT 2009

Documents like MS-SAMR describe prococols that manipulate and open
'domains' in the AD server.  Examples include: SamrLookupDomainInSamServer (Opnum 5)

This operation seems to describe the ability to lookup different domains
by name.  Presumably multiple domains can be looked up, and
SamrOpenDomain (Opnum 7) can open any domain by SID.

Other protocols in the AD suite of protocols appear to similarly be able
to handle multiple domains.  It appears designed with this generality in
mind, but not implemented in Microsoft's products.  

However, as I look at other protocols, it becomes clear that there is a
strict notion of a single 'primary domain' of a particular server.  The
DSSETUP call dssetup_DsRoleGetPrimaryDomainInformation and some LSA
calls clearly only call out a single domain as supported.

Anyway, the reason I ask is that I'm working to rip out extra code in
Samba that is lovely and general, but is also unweildy and unnececery.
(But of course to improve support for multiple domains via trusts).  

I just want to check I do not mis-understand, before I wield the axe.

Would you agree with the statement:

While early calls in NT provided for a very high degree of generality in
supporting the concept of multiple domains being hosted on a single
server, it was not implemented, and in AD numerous technical barriers
and later design choices mean that each AD server must host only a
single domain (not even other domains in a local AD tree).  Access to
other domains is via trusts in the tree, forest and between forests.


Andrew Bartlett

Andrew Bartlett
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/cifs-protocol/attachments/20090520/c1983b6d/attachment.bin

More information about the cifs-protocol mailing list