[Samba] Multiple domain and trust relationship

mathias dufresne infractory at gmail.com
Mon Oct 12 09:08:31 UTC 2015


Multi-sites AD does not mean multi-domain AD. You do not must build trust
relationship.

Building an AD for a company is not trivial. It's a structural piece of IT
which must be thought. Needing RTFM and understanding why you would go into
some direction or another.

Trust relationships can be what you need, but not necessarily. It depends
on what you need.

Microsoft does not advice to use trust relationship if not needed, that's
why you must first understand what they are, why they could be useful for
you, why they are not and finally make your own decision. According to your
company needs and possibilities.

Samba 4.3.x comes with initial support of these trust relationships, with
some limitations (see at least 4.3.0 changelog). I have no real idea about
what are able previous versions of Samba regarding this feature, except
there is much more limitations.

Lot of companies are using one AD domain on multi-sites, so to answer you
shortly: you can have one domain for multiple sites. Is it what you need? I
can't tell, you only can.

Cheers,

mathias

2015-10-08 18:20 GMT+02:00 Julien Deloubes <julien.deloubes at gmail.com>:

> Hello guys,
> i use Samba 4 AD  (4.2.1) for a small company.
> I use a domain which is a subdomain of our internal DNS domain (
> directory.mydomain.io)
> Now my company will open several sites in different countries.
> I was wondering what is the actual limitations of Samba4 concerning the
> multi domain (i'm not a Windows guy and have very limited knowledge about
> AD).
> I read about trust relationship limitations (can be trusted but cannot
> trust) so does this mean that for the moment i'm stuck with one domain?
>
> What is my option considering multisites, could i continue to use only one
> domain (with RODC for example)?
>
> Thanks
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>


More information about the samba mailing list