Solved

Creating Trusts "the Account already Exists"

Posted on 2004-04-06
8
464 Views
Last Modified: 2013-12-23
I am trying to set up a 2 way trust between a Nt4 domain and a win2k domain.

When i try to add the win2k domain to the trusting Domain on the NT4 domain i get the message that "the Account already Exists". this is the only section i have a problem with.

Any Ideas?
0
Comment
Question by:whookie
  • 4
  • 2
  • 2
8 Comments
 
LVL 33

Accepted Solution

by:
MikeKane earned 500 total points
Comment Utility
Account created when a trust relationship is established between two domains. To implement the trust, an interdomain trust account is created in the directory db of the trustED domain. The account is created when the administrator of the trusted domain defines the trusting domain using the admin application User Manager for Domains. The account has the USER_INTERDOMAIN_TRUST_ACCOUNT bit set which identifies it as only used for trust relationships. The account is hidden and cannot be modified. The password and account is used when establishing a session with the trustING domain. The account is only viewable via registry on the PDC of the trustED domain: HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Accounts\Users\Names\<trustEDdomainname>$.
0
 
LVL 33

Expert Comment

by:MikeKane
Comment Utility
0
 

Author Comment

by:whookie
Comment Utility
Usefull information but i don't think it solves my problem. I have no problem setting up the trusted domain entries on both the Win2k and NT4 domains. It is when i try to add the entry for trusting domains on the nt4 domain that i receive my error.

I also looked in the registry keys that you provided and i didn't have any entries deaper that \sam\sam
0
 
LVL 33

Expert Comment

by:MikeKane
Comment Utility
Perhaps, then, a diagram showing the different domains and the trusts for those domains that you want to setup.  IT would also help me if you specified where trusts already exist and where new ones are to be created.

Thanks
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 

Author Comment

by:whookie
Comment Utility
OK here we go.

chc-nt (nt4 Domain) and    Commhealth (win2k Domain) They are both at the same physical location just in different domains.

I want to set up a 2 way trust between these to domains. Making chc-nt a trusted domain to the commhealth domain is working. it is when i try to make CHC-nt a trusting domain that i get the error.
0
 
LVL 33

Expert Comment

by:MikeKane
Comment Utility
With trusts, I found that it's sometimes easier just to blow away the entire trust and recreate it.      With only 2 domains, that should be pretty easy.    
 

Here are the How-to's I'm sure you already know, but worth double checking:
 (http://support.microsoft.com/default.aspx?scid=kb;en-us;306733&Product=win2000)
 
Create a Two-Way Trust
To create a two-way trust between a Windows 2000 domain and the Windows NT 4.0 domain:
On the Windows 2000 domain controller (DC), click Start, point to Programs, point to Administrative Tools, and then click Active Directory Domains and Trusts. Right-click the appropriate domain name, click Properties, and then click the Trusts tab.
Under Domains that trust this domain, click Add.
In Trusting Domain, type NTDOMAIN, and then type a password. Note that the password must meet the minimum password requirements for the trusting domain.
On the Windows NT 4.0 primary DC (PDC), start User Manager For Domains. Open Policies, and then open Trust Relationships. Under Trusting Domain, click Add.
In Trusting Domain, type W2KDOMAIN, and then type the appropriate password.
On the Windows 2000-based computer, under Domains trusted by this domain on the Trust tab, click Add, type NTDOMAIN and the appropriate password. You should receive an informational message that states "The trusted domain has been added and the trust has been verified."
On the Windows NT 4.0 PDC, add the W2KDOMAIN domain as a trusted domain, and type the appropriate password. You should receive an informational message that states "Trust Relationship with W2KDOMAIN successfully established." The two-way trust has been established.





Also,
http://support.microsoft.com/default.aspx?scid=kb;en-us;309682&Product=win2000

and
http://support.microsoft.com/default.aspx?scid=kb;en-us;228477&Product=win2000
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
Make sure you dont have a computer account already in Active Directory Users and Computers (2000) or Server Manager (NT) that matches the domain controller in the domain you are trying to trust.
0
 
LVL 30

Expert Comment

by:Gareth Gudger
Comment Utility
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Forest Trust  vs ADFS 4 150
cant access shared folders 22 46
Sonicwall AP 3 47
ADMT Intra Forest migration questions 7 66
A brief overview to explain gateways, default gateways and static routes OR NO - you CANNOT have two default gateways on the same server, PC or other Windows-based network device. In simple terms a gateway is formed when a computer such as a serv…
We recently endured a series of broadcast storms that caused our ISP to shut us down for brief periods of time. After going through a multitude of tests, we determined that the issue was related to Intel NIC drivers on some new HP desktop computers …
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now