Solved

Domain Trust between server 2003 and 2000 breakdown

Posted on 2006-07-01
4
2,802 Views
Last Modified: 2012-08-13
I performed the following steps:
 - Created a new installation of server 2003 (std)
 - Set it up as a domain controller with DNS, WINS etc.,
 - Created a two-way trust between it and an already existing w2k domain with domain-wide authentication (This was created from the w2k3 domain, if that's useful)

All appeared to be ok until after about 24 hrs the trust broke down, but only in one direction (w2k domain could not connect to w2k3). The other direction appears to be working fine.

The error from the w2k DC when I try to verify the trust is: Information from the primary domain controller for the domain w2k3.loc cannot be obtained because: The RPC server is unavailable. Make sure that the PDC is operating properly and then try again.

The error from the w2k3 DC when I try to validate the trust is: Windows cannot find a domain controller for the w2k.loc domain. Verify that a DC is available and then try again.

Any ideas?
0
Comment
Question by:windylad
  • 2
4 Comments
 
LVL 15

Accepted Solution

by:
harleyjd earned 500 total points
ID: 17023740
damn, that sounds like what I went through on Thursday and Friday.

I have nice DNS replication set up between domains, but I could not get the trust to stay in-place once I had it established.

In the end I removed all netbios names from the lmhosts file at each end, and stopped the DC's from registering and using WINS. Once I did that I got the trust validated no problems.

So, make sure your DNS is completely replicated by either using secondaries at either end, or using forwarders (and the cool 2003 conditional forwarders!) then take out the WINS server from the DC's


0
 
LVL 8

Expert Comment

by:bilbus
ID: 17025130
sounds like a dns problem. What do you get when you ping
domainname.com
dc1.domainname.com
dc2.domainname.com

(dc.domainname.com replace with name of domain controlers and name of domain)

do this on both domains and see if you can ping all the names.

post here with your status
0
 

Author Comment

by:windylad
ID: 17030658
There was indeed a problem with the DNS setup. I did have forwarders configured, but there was a problem with the replication due to zone transfer enabling.
I have corrected the problem and re-created forwarders and trusts from scratch. All is good at the moment, but I'll leave it a day or so before closing this question and allocating points. Thanks for the help guys.
0
 

Author Comment

by:windylad
ID: 17050919
That looks like it was the problem. It has been up and running for a few days now with access in both directions. Many Thanks for the help guys.
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
by Batuhan Cetin Within the dynamic life of an IT administrator, we hold many information in our minds like user names, passwords, IDs, phone numbers, incomes, service tags, bills and the order from our wives to buy milk when coming back to home.…
This tutorial gives a high-level tour of the interface of Marketo (a marketing automation tool to help businesses track and engage prospective customers and drive them to purchase). You will see the main areas including Marketing Activities, Design …
With the power of JIRA, there's an unlimited number of ways you can customize it, use it and benefit from it. With that in mind, there's bound to be things that I wasn't able to cover in this course. With this summary we'll look at some places to go…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now