Solved

Child Domain logon problem

Posted on 2002-06-20
14
182 Views
Last Modified: 2010-04-13
I have a Win2000 network with a parent and child domain. The domain is using active directory and seems fully functional EXCEPT members of the child domain usually don't get their password validated until the second or third attempt at logging on. The error reads 'The domain password you supplied is not correct, or access to your logon server has been denied' - neither of which is true. The error comes back almost instantly - like not enough time has passed to really check. The child domain has 3 servers and the validating servers sit on the same switch so it isn't the physical network. The parent domain has no problems.
I have no idea where to start tracking down the problem.
0
Comment
Question by:sacs
14 Comments
 
LVL 4

Expert Comment

by:Nevaar
ID: 7098543
Check the DNS entries for your child domain controllers.  Are they all showing up (the SRV reocrds)?  Are all the records correct (they really point to the domain controllers)?
0
 
LVL 17

Expert Comment

by:mikecr
ID: 7099234
I might have to agree that DNS is the issue. You may be having a resolution problem that could be causing this. Your domain should have the authoritative DNS server where as the child should have a secondary to the primary.
0
 

Author Comment

by:sacs
ID: 7102382
According to Microsoft (look at Q286753)child DNS should be in active directory and only some information is stored in the child DNS.

It could be DNS is incorrectly functioning but if the DNS in the parent and child domain show no errors and it's setup according to Microsoft how is it tested?
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:sacs
ID: 7102500
According to Microsoft (look at Q286753)child DNS should be in active directory and only some information is stored in the child DNS.

It could be DNS is incorrectly functioning but if the DNS in the parent and child domain show no errors and it's setup according to Microsoft how is it tested?
0
 
LVL 17

Expert Comment

by:mikecr
ID: 7103382
Normally you would create another zone on the DNS server in the primary domain for the child and have a secondary DNS server in the child domain for name resolution. Is this how your currently set up?
0
 

Author Comment

by:sacs
ID: 7105740
Mikecr - I have a root DNS - I know it's the root as it has no hints lookup table. I have another DC DNS with Active Directory and a third server as a secondary DNS (all are in the parent domain and have a full list of clients).
In the child domain I have a DC with DNS active directory intergration but its has only some of the information from the parent and the information it has is only to do with the child.

I would understand Micrsoft's logic if the child domain only carried information about itself but the DNS doesn't even have a full set of the child information.
0
 
LVL 17

Expert Comment

by:mikecr
ID: 7107094
Go into the properties of the DNS server then and set up a forwarder to the DNS server of your primary domain. See if this helps, also, check the event viewer of the domain controller and see what errors it is logging under system and security and post them here.
0
 

Author Comment

by:sacs
ID: 7109721
Forwarding was already checked from the Child to the Parent - over the last week there have been no error reports by either the parent and child DNS server.
0
 
LVL 17

Expert Comment

by:mikecr
ID: 7110189
Have you gone into sites and services and created the site for your child domain? Do you have all Windows 2000 clients?
0
 

Author Comment

by:sacs
ID: 7112160
In site and services I have only the default container - default-first-site-name which contains a folder servers - which has both parent and child servers - why create another container?
I have both Win2000 and Win98 clients. I have mainly Win 98 in the child - made me think to check with the Win2000 machines in the child domain if they too have the problem.
0
 
LVL 17

Expert Comment

by:mikecr
ID: 7113216
Are you using the AD client on the Windows 98 machines? The reason I asked about the site is if you have different subnets with domain controllers on them you need to specify them in Sites and Services. Whenever the client logs in then it knows where the closest domain controller is to log into and the servers know how to set up the KCC and replicate between themselves properly.
0
 

Author Comment

by:sacs
ID: 7322828
Resolution - we ghost our machines and the win 98 copy we used has some corruption that affected the wins resolution
0
 
LVL 1

Expert Comment

by:netwiz562
ID: 8962263
---- CLEAN UP ----

sacs,
No comment has been added lately (284 days), so it's time to clean up this TA.
I will leave a recommendation in the Cleanup topic area for this question:

RECOMMENDATION: [ PAQ/Refund ]

Please leave any comments here within the next seven days.

¡PLEASE DO NOT ACCEPT THIS COMMENT AS AN ANSWER!

------------------------------
Rajiv Makhijani
EE Cleanup Volunteer
0
 

Accepted Solution

by:
PashaMod earned 0 total points
ID: 9014067
Per recommendation

PashaMod
CS Moderator
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In threads here at EE, each comment has a unique Identifier (ID). It is easy to get the full path for an ID via the right-click context menu. However, we often want to post a short link within a thread rather than the full link. This article shows a…
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
I've attached the XLSM Excel spreadsheet I used in the video and also text files containing the macros used below. https://filedb.experts-exchange.com/incoming/2017/03_w12/1151775/Permutations.txt https://filedb.experts-exchange.com/incoming/201…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question