[Samba] Multiple domain and trust relationship

Julien Deloubes julien.deloubes at gmail.com
Mon Oct 12 15:20:36 UTC 2015


Thanks Mathias,
will read some MS docs about that.
My concern was mainly about scalability, is my simple internal domain could
evolve to something bigger and what will be the best way to do that.



2015-10-12 11:08 GMT+02:00 mathias dufresne <infractory at gmail.com>:

> Multi-sites AD does not mean multi-domain AD. You do not must build trust
> relationship.
>
> Building an AD for a company is not trivial. It's a structural piece of IT
> which must be thought. Needing RTFM and understanding why you would go into
> some direction or another.
>
> Trust relationships can be what you need, but not necessarily. It depends
> on what you need.
>
> Microsoft does not advice to use trust relationship if not needed, that's
> why you must first understand what they are, why they could be useful for
> you, why they are not and finally make your own decision. According to your
> company needs and possibilities.
>
> Samba 4.3.x comes with initial support of these trust relationships, with
> some limitations (see at least 4.3.0 changelog). I have no real idea about
> what are able previous versions of Samba regarding this feature, except
> there is much more limitations.
>
> Lot of companies are using one AD domain on multi-sites, so to answer you
> shortly: you can have one domain for multiple sites. Is it what you need? I
> can't tell, you only can.
>
> Cheers,
>
> mathias
>
> 2015-10-08 18:20 GMT+02:00 Julien Deloubes <julien.deloubes at gmail.com>:
>
> > Hello guys,
> > i use Samba 4 AD  (4.2.1) for a small company.
> > I use a domain which is a subdomain of our internal DNS domain (
> > directory.mydomain.io)
> > Now my company will open several sites in different countries.
> > I was wondering what is the actual limitations of Samba4 concerning the
> > multi domain (i'm not a Windows guy and have very limited knowledge about
> > AD).
> > I read about trust relationship limitations (can be trusted but cannot
> > trust) so does this mean that for the moment i'm stuck with one domain?
> >
> > What is my option considering multisites, could i continue to use only
> one
> > domain (with RODC for example)?
> >
> > Thanks
> > --
> > To unsubscribe from this list go to the following URL and read the
> > instructions:  https://lists.samba.org/mailman/options/samba
> >
> --
> To unsubscribe from this list go to the following URL and read the
> instructions:  https://lists.samba.org/mailman/options/samba
>


More information about the samba mailing list