Subscribe to Windows IT Pro
November 10, 2003 12:00 AM

NT Gatekeeper: Understanding Interdomain Trust Relationship Limits

Windows IT Pro
InstantDoc ID #40575
Rating: (0)

Does Windows NT Server 4.0 limit the number of domain trust relationships?

NT Server 4.0 has a practical limit of 128 trust relationships that originate from one domain and a theoretical limit of 256 trusts that originate from one domain. The limiting factor is the Local Security Authority (LSA) secrets, which are private data objects that NT uses to store security information. NT Server 4.0 limits the number of LSA secrets to 256. An outgoing trust relationship consumes one LSA secret for every DC in the domain. Because LSA secrets are also used for other purposes (e.g., to save the passwords for service accounts), Microsoft recommends that you use no more than half of the 256 LSA secrets for interdomain trust relationships.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.