<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx</link><description>Rob and Mike here. We're asked, many times, why a user does not authenticate against a local domain controller in the same site when logging on across a forest. We've setup the most common scenario to help explain how domain locator works for user logons</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3315084</link><pubDate>Wed, 24 Feb 2010 16:57:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3315084</guid><dc:creator>NedPyle [MSFT]</dc:creator><description>&lt;p&gt;You're out of them.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3315084" width="1" height="1"&gt;</description></item><item><title>re: Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3315075</link><pubDate>Wed, 24 Feb 2010 16:21:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3315075</guid><dc:creator>ibabeu</dc:creator><description>&lt;p&gt;Ok, so if you can't match the site names, it's an external trust, and are using DNS forwarding (so you can't simply put up a stub domain) what are your options?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3315075" width="1" height="1"&gt;</description></item><item><title>re: Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3244711</link><pubDate>Fri, 22 May 2009 23:10:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3244711</guid><dc:creator>timmay</dc:creator><description>&lt;p&gt;This article does a great job of explaining authentication between domains using a forest trust.&lt;/p&gt;
&lt;p&gt;I'm trying to fix slowdowns when the trust is between domains with no forest trust, i.e. External. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;We see the same behaviour as above in our traces but the trusted domain controllers are not accessible to members of the resource domain. &amp;nbsp;DNS is available because the trusting domain DCs are forwarding the requests through. &amp;nbsp;In the end the devices in the trusting domain spend a good deal of time, ~20 sec, trying to contact DCs in the external trusted domain for Kerberos authentication. &amp;nbsp;Only when they fail entirely will go to their own DC.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3244711" width="1" height="1"&gt;</description></item><item><title>re: Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3133469</link><pubDate>Tue, 07 Oct 2008 15:58:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3133469</guid><dc:creator>Michael Hildebrand - MSFT</dc:creator><description>&lt;p&gt;Great info on a real-world issue - 'how to effectively use multiple forests?' &amp;nbsp;Great work, bloggers!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3133469" width="1" height="1"&gt;</description></item><item><title>re: Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3129901</link><pubDate>Mon, 29 Sep 2008 15:54:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3129901</guid><dc:creator>NedPyle [MSFT]</dc:creator><description>&lt;p&gt;Great catch bday! That has been fixed.&lt;/p&gt;
&lt;p&gt;- Ned&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3129901" width="1" height="1"&gt;</description></item><item><title>re: Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3128695</link><pubDate>Fri, 26 Sep 2008 06:52:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3128695</guid><dc:creator>Brian Day [MSFT]</dc:creator><description>&lt;p&gt;Great post, it really makes it nice and clear to understand and fix. &lt;/p&gt;
&lt;p&gt;One quick comment though on this paragraph;&lt;/p&gt;
&lt;p&gt;BEGIN_SNIP&lt;/p&gt;
&lt;p&gt;The DNS server's response to the above request includes a resource record for every domain controller in the user's domain. Since the client receives the list of domain controllers in no particular order this result is usually the cause as to why the domain controller locator does use the closest domain controller for authentication.&lt;/p&gt;
&lt;p&gt;END_SNIP&lt;/p&gt;
&lt;p&gt;...shouldn't it say &amp;quot;does not use&amp;quot; in the second sentence?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3128695" width="1" height="1"&gt;</description></item><item><title>Domain Locator Across a Forest Trust</title><link>http://blogs.technet.com/b/askds/archive/2008/09/24/domain-locator-across-a-forest-trust.aspx#3128222</link><pubDate>Thu, 25 Sep 2008 13:28:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3128222</guid><dc:creator>Domain Locator Across a Forest Trust</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.ditii.com/2008/09/25/domain-locator-across-a-forest-trust/"&gt;http://www.ditii.com/2008/09/25/domain-locator-across-a-forest-trust/&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3128222" width="1" height="1"&gt;</description></item></channel></rss>