Windows Server 2003
1832609 Members
2246 Online
110043 Solutions
New Discussion

Windows 2003\Exchange Authentication

 
sync23
Occasional Contributor

Windows 2003\Exchange Authentication

I have an Exchange 2003 backend server in a Windows 2003 domain "test.local"
I have a WIndows 2003 subdomain "subdomain.test.local"

I also have a Windows 2003 domain in a seperate forest called "internal.org", there is a 2 way external non-transitive trust between this and "test.local"

The domain controllers from each domain can communicate with each other, but the Exchange server can only communicate with the DC in its own domain (test.local)

I can authenticate users in the "internal.org" domain to Exchange from the domain controller in test.local (i.e. using the non-transitive trust), BUT, if I try and authenticate using an account in the subdomain, the MAPI (or OWA) logon just hangs.
However, I do see a successful logon event on the subdomain DC.

I figure this is something to do with NTLM\Kerberos. I ideally need to be able to auth users via the local DC to Exchange, as in production there will be LOTS of DCs out on site at the end of puny links. i.e. I want Exchange to pass the auth request to its local DC (as is the case with the 2 way manual trust)

any ideas?

thanks
1 REPLY 1
Marcus Roxnäs
New Member

Re: Windows 2003\Exchange Authentication

http://redmondmag.com/columns/article.asp?EditorialsID=593

Have you checked the part, in your AD where you specifies who is allowed to authenticate...