Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


January 24, 2000

Additional Windows 2000 Glossary Entries


RSS
Subscribe to Windows IT Pro | See More Windows 2000 Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

This week, I present the fourth in an occasional series of Windows 2000 Ready columns that I'll devote to defining new Windows 2000 (Win2K) terms and concepts. With this series, I'll be compiling a Win2K glossary for the Windows NT Magazine Web site. If you'd like me to address any particular Win2K topics, acronyms, or concepts, email me at zubair@winntmag.com.

ADSI
Active Directory Service Interface (ADSI) defines a set of COM interfaces that let directory service client applications access network directory services such as Active Directory (AD). With ADSI, clients can use one set of interfaces to communicate with any namespace that supports ADSI implementation. Instead of making network-specific API calls, clients can take advantage of ADSI to access namespace services. In addition to standard COM features, ADSI supports Java, Visual Basic (VB), VBScript, C, C++, and ActiveX technology.

Attribute
An attribute is a characteristic or property of an AD object. Attribute values define all AD objects. For example, a user object's attributes (e.g., first name, last name, phone number) define the user object. The schema defines the attributes. You can apply one attribute definition to several different classes because the schema defines attributes and classes separately. For example, an attribute named location can apply to two different classes: printers and computers.

CA
A Certificate Authority (CA) is a service that issues digital certificates to individuals, computers, and organizations. A CA can be either one that you create within your organization by installing Win2K Certificate Services or a third-party CA such as VeriSign. A CA is responsible for publishing a Certification Revocation List (CRL). A root CA, also known as the root authority, is the most trusted CA in an organization. Typically, organizations use root CAs only to issue certificates to subordinate CAs, which are CAs that a root CA or another subordinate CA has certified. Generally, subordinate CAs issue certificates for secure email, smart card authentication, and other authentications. A root CA and subordinate CAs form a certification hierarchy.

Forest
A forest is a collection of one or more AD trees that connect through transitive bidirectional Kerberos trust relationships. Trees in a forest share several things, including a common schema, a global catalog, and certain configuration information, but they don't form a contiguous namespace. With one logon, users can access resources in any domain in a forest because of transitive trusts. Only transitive trusts exist between Win2K domains in the same forest; you can't create nontransitive trusts between Win2K domains in the same forest. However, the only trust you can create between two forests is a nontransitive trust. Throughout a forest, you can have only one schema master domain controller, which handles updates and changes to schema, and one domain naming master, which handles addition or removal of domains in the forest.

Group Policy
A Group Policy is a policy that an administrator applies to a group of users and computers within an organizational unit (OU). A group policy object (GPO) is a collection of such policies. Group Policies in Win2K take the NT 4.0 system policy concept to the next level: You can apply Registry-based changes, as you could with NT system policies, but Group Policies also let you perform various tasks, including deploying applications on client desktops, configuring startup-shutdown and logon-logoff scripts, and enforcing domain security. Although Win2K's Group Policies replace any NT system policies you created with System Policy Editor (SPE), Win2K still supports system policies. By default, a Group Policy updates every 5 minutes on domain controllers and every 90 minutes on clients, with a random offset of 0 to 30 minutes.

Kerberos V5 Authentication
Kerberos V5, the primary security protocol that Win2K uses for authentication, uses encrypted authentication instead of sending clear-text passwords over the wire. Kerberos refers to several things: Kerberos is the Authentication Service (AS), the protocol that AS uses, and the code that implements AS. Kerberos V5 authentication issues tickets for accessing services on the network. The Kerberos protocol consists of several subprotocols and can operate across domains. The Kerberos V5 authentication service, Key Distribution Center (KDC), runs as a service on each domain controller.

Transitive Trust
A transitive trust is a trust relationship that exists by default between domains in a Win2K tree or forest. Transitive trusts also exist inherently between trees in a forest. With transitive behavior, if domain X trusts domain Y, and domain Y trusts domain Z, then domain X also trusts domain Z. When a Win2K domain joins an existing tree, a two-way transitive trust establishes automatically. In NT, two-way trusts are really two one-way trusts that establish one at a time. The transitive trusts in Win2K are bidirectional and allow authentication and access to resources all across a forest.

End of Article



Reader Comments
Very helpful article. I have just started my W2k training while finishing MCSE v4. Is this all there is that is new in W2k. I hope not. I would like to know more definitions and differences.



Derek Keith Duvall January 31, 2000


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Accessing Database Data with ADO

...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Internet Explorer 8 Beta 2 Goes Public

Microsoft on Wednesday shipped the Beta 2 version of its upcoming Internet Explorer (IE) 8 Web browser. This version of the product, which will be made available free to Windows XP, Vista, 2003, and 2008 users, adds many functional advances and some new ...


Windows OSs Whitepapers Replay for Exchange: Enterprise Protection and an Affordable Price

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Maximize your SharePoint Investment – 8 Cities
Discover best practices and tips for both architecting and administering SharePoint. Early Bird Price of $99 through Sept 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Increase Application Performance
Free White Paper by Editor's Best winner, Texas Memory Systems.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing