Why is Forest level trust instead of REALM level trust between IDM and Active Directory.

Solution Verified - Updated -

Issue

- Why is a Forest Level Trust required between IDM and AD and not a REALM level trust. Are these different?
- When using the WebUI, exactly what changes are performed in IDM to the AD domain and how is this being done?
- When manually creating a REALM level trust in AD and then using the ipa-trust-add --type=ad --shared-secret options in IDM, is there any reason that you can think of that this wouldn't work?
- Does IDM as part of the Trust Creation create any Bind or KeyTab files for authentication with AD?

Environment

Red Hat Enterprise Linux 7.x
Active Directory.

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content