Penn State Mark Independent Active Directory forest trust to the Access Account Kerberos realm Information Technology Services

 

How To: How to Setup a Direct Trust


Prerequisites

  1. A functioning Forest.
  2. An Enterprise admin account.
  3. A Domain Controller in the Root Domain.
  4. Apply for a direct trust and receive the trust password.
  5. Windows® Support Tools installed (located on the installation CD).

Step 1: Create the Trust

  1. Log on to the Domain Controller with your enterprise administrative account.
  2. Click Start &ndash>Run and enter domain.msc command.
  3. Click <OK>.
  4. Active Directory Domains and Trusts window

  5. Right-click the name of your rootdomain.
  6. Choose Properties.
  7. Click the Trusts tab.
  8. Trust Properties window

  9. Click <New Trust>.
  10. Click <Next>.
  11. Enter dce.psu.edu in the Name: field.
  12. New Trust Wizard - New Trust Name screen

  13. Click <Next>.
  14. Click the Realm Trust radio button.
  15. New Trust Wizard - Trust Type screen

  16. Click <Next>
  17. Click either the Transitive or the Nontransitive radio button. Click Transitive if you plan to have any child domains use the Realm Trust.
  18. New Trust Wizard - Transitivity of Trust screen

  19. Click <Next>.
  20. Click the One-way; outgoing radio button.
  21. New Trust Wizard - Direction of Trust screen

  22. Click <Next>.
  23. Enter the trust password supplied to you.
  24. New Trust Wizard - Trust password screen

  25. Click <Next>.
  26. Click <Next>.
  27. Review the information.
  28. Click <Finish>.
  29. Click <OK>.

Step 2: Setting the KDC Registry entries

  1. Run the Registry file, per the instructions noted in the Setting Up the Registry Entries for the K5 KDCs section of this site.

Step 3: Creating the Appropriate Skeleton Accounts

NOTE: Your organization will need to create and maintain skeleton or real accounts for anyone who needs to log in to your forest.

  1. Log in as a user with privileges to create user accounts.
  2. Click Start &ndash>Run and enter the dsa.msc command.
  3. Click <OK>.
  4. Choose Users.
  5. Active Directory Users and Computers - Advanced Features window

  6. Select View &ndash>Advanced Features
  7. Active Directory Users and Computers - Advanced Features window

  8. Right-click Users.
  9. Choose New->User.
  10. Fill in the appropriate data.
  11. After the user is created, right-click the user's name, listed in the right-side panel.
  12. Choose Name Mappings.
  13. Click the Kerberos Tab.
  14. Name Mappings pull-down menu window

  15. Click <Add>.
  16. Enter the username@dce.psu.edu (for example, xyz123@dce.psu.edu).
  17. Security Identity Mapping window

  18. Click <OK>.
  19. Click <OK>.

Test the Configuration

  1. To test the configuration, log in with the specified username (per the above; for example, xyz123@dce.psu.edu) and password (Penn State Access Account password).
  2. If you receive the message, "Local policy of this system does not permit you to log on interactively" or you are able to log on successfully, then the trust works.

The Pennsylvania State University ©2006. All rights reserved.
Alternative Media - Nondiscrimination Statement
This site maintained by Academic Services and Emerging Technologies, a unit of Information Technology Services.

Comments and suggestions may be directed to asetcomm@psu.edu.

Last revised: Friday, May 19, 2006.