[Samba] samba4 in AD with multiple domains

Andrew Bartlett abartlet at samba.org
Wed Nov 27 16:10:43 MST 2013

On Tue, 2013-11-26 at 11:51 -0500, Michael Brown wrote:
>  From the FAQ:
> Q: Does Samba support trust relationship with AD?
> A: Trusts are currently not finished implemented. Samba can be trusted, 
> but can't trust yet.
> Does this mean that in a single-forest multiple-domain AD environment, 
> samba will only know about accounts in it's own domain? Or does this 
> statement apply to forest-forest trusts?

In the AD DC, there is some support for inter-forest trusts, mostly
because we didn't remove trusts from our KDC, but very little else in
Samba knows about it.  The LSA server can set up and manage some aspects
of trusts. 

Does this clarify things for you?

Andrew Bartlett

Andrew Bartlett
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT          http://catalyst.net.nz/services/samba

More information about the samba mailing list