I've had no problems in the past link CE's to AD's but have a problem now in that I have a central ads which is schoolarea.sch.local but then there are multiple sub "child" domains set up as schoola.schoolarea.sch.local
all of the child domains are part of the same AD forest , inital tests have not worked. We are pointing at the root domain using the base dc=schoolarea,dc=sch,dc=local with an account in the root domain with rights to search all child domains.
Its know its not a problem if the sub entities are OU's rather than child domains but was looking for any advise on if anybody has ever gotten this working?
Also has anybody ever managed single sign-on for ADS and IE using XP clients, my current understanding is this is not possible because of the restrictions of the kerberos authenitcation requests. NTLM isn't really an option either because of the inter domain trusts.
Cheers
Mark