Solved

Domain Trust between server 2003 and 2000 breakdown

Posted on 2006-07-01
4
2,778 Views
Last Modified: 2012-08-13
I performed the following steps:
 - Created a new installation of server 2003 (std)
 - Set it up as a domain controller with DNS, WINS etc.,
 - Created a two-way trust between it and an already existing w2k domain with domain-wide authentication (This was created from the w2k3 domain, if that's useful)

All appeared to be ok until after about 24 hrs the trust broke down, but only in one direction (w2k domain could not connect to w2k3). The other direction appears to be working fine.

The error from the w2k DC when I try to verify the trust is: Information from the primary domain controller for the domain w2k3.loc cannot be obtained because: The RPC server is unavailable. Make sure that the PDC is operating properly and then try again.

The error from the w2k3 DC when I try to validate the trust is: Windows cannot find a domain controller for the w2k.loc domain. Verify that a DC is available and then try again.

Any ideas?
0
Comment
Question by:windylad
  • 2
4 Comments
 
LVL 15

Accepted Solution

by:
harleyjd earned 500 total points
ID: 17023740
damn, that sounds like what I went through on Thursday and Friday.

I have nice DNS replication set up between domains, but I could not get the trust to stay in-place once I had it established.

In the end I removed all netbios names from the lmhosts file at each end, and stopped the DC's from registering and using WINS. Once I did that I got the trust validated no problems.

So, make sure your DNS is completely replicated by either using secondaries at either end, or using forwarders (and the cool 2003 conditional forwarders!) then take out the WINS server from the DC's


0
 
LVL 8

Expert Comment

by:bilbus
ID: 17025130
sounds like a dns problem. What do you get when you ping
domainname.com
dc1.domainname.com
dc2.domainname.com

(dc.domainname.com replace with name of domain controlers and name of domain)

do this on both domains and see if you can ping all the names.

post here with your status
0
 

Author Comment

by:windylad
ID: 17030658
There was indeed a problem with the DNS setup. I did have forwarders configured, but there was a problem with the replication due to zone transfer enabling.
I have corrected the problem and re-created forwarders and trusts from scratch. All is good at the moment, but I'll leave it a day or so before closing this question and allocating points. Thanks for the help guys.
0
 

Author Comment

by:windylad
ID: 17050919
That looks like it was the problem. It has been up and running for a few days now with access in both directions. Many Thanks for the help guys.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now