Domain Trust One Way
Make sure both ipa and ad users are resolvable.
Domain trust one way. In this exercise i m attempting to create a one way external trust with another domain. Enter a password for the trust. A trust relationship can be one way or two way. A one way trust is a unidirectional authentication path created between two domains.
Make sure removing a trust relationship removes the keytab from the filesystem. Make sure you choose a one way. I have domain1 with 2 domain controllers and domain2 with only 1 domain controller. Your vendor would not have access resources in your forest with a one way trust so the risk to your environment is somewhat minimized on ad ad functional level.
In this topic the on premises domain is the trusted or inbound. Here you will have enter the other forests domain choose trust with a windows domain then next. Now i would like domain1 users to access domain2 but domain2 users can t access domain1 s resources. Incoming this is really important if you don t choose this domain only it will not create a one way trust in the way that we want.
Establish a one way trust relationship with an ad domain. Make sure that sssd handles re establishing a trust relationship.