域的信任分为单向信任和域的多项信任。

如下图:

clip_image002

让xapc.com 信任ctc.com。

网络环境的搭建:

clip_image004

A:

clip_image006

C:

clip_image008

B:

clip_image010

clip_image012

先做单向信任,(注意,首先由被信任方开始发起信任)

首先在C D上做 DNS转发:

在C上:

clip_image014

clip_image016

测试:

C:\>nslookup

DNS request timed out.

timeout was 2 seconds.

*** Can't find server name for address 192.168.1.4: Timed out

Default Server: UnKnown

Address: 192.168.1.4

> winc.xapc.com

Server: UnKnown

Address: 192.168.1.4

Name: winc.xapc.com

Address: 192.168.1.2

> wind.ctc.com

Server: UnKnown

Address: 192.168.1.4

Name: wind.ctc.com

Address: 192.168.1.4

> server 192.168.1.2

DNS request timed out.

timeout was 2 seconds.

Default Server: [192.168.1.2]

Address: 192.168.1.2

> winc.xapc.com

Server: [192.168.1.2]

Address: 192.168.1.2

Name: winc.xapc.com

Address: 192.168.1.2

> wind.ctc.com

Server: [192.168.1.2]

Address: 192.168.1.2

Name: wind.ctc.com

Address: 192.168.1.4

在D计算机上开始做信任:

clip_image018

clip_image020

填写的是对方的域(目标地址,就是你想访问的资源所在的域)

clip_image022

单向:内传,用户到资源所在的域。(被信任到信任)

clip_image024

信任必须是两者(被信任和信任)

clip_image026

clip_image028

clip_image030

clip_image032

clip_image034

clip_image036

(D上也可以查看)

在C:上查看单向信任关系的建立:

clip_image038

单向信任建立成功:

开始测试:

在D的CTC.COM域上建立用户:

clip_image040

clip_image042

clip_image044

测试成功

现在做双向信任:

在原有的单向信任的基础之上:

在C上:

clip_image046

clip_image048

clip_image050

把单向的信任转化成双向信任:

clip_image052

clip_image054

clip_image056

clip_image058

clip_image060

clip_image062

clip_image064

clip_image066

双向信任完成:

测试:

clip_image068

clip_image070

 

 

双向信任成功