Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Two way trust only works on PDC?

Posted on 2011-02-25
6
517 Views
Last Modified: 2012-06-27
I have a new Windows server 2008 R2 domain and forest (both functional levels at 2008 R2)
with a two way trust to another domain in a different forest (both 2000 mixed functional level)

so the setup is
Forest  A Domain A is 2008 R2
Forest  B Domain B is server 2003 running forest/domain 2000 mixed functional level.

on the PDC in Domain A  I can share files and see accounts in Domain B

But on any other member server or other domain controllers in Forest A, when I try to share a file and choose permissions, I can see domain B listed, but I only see about a dozen "built-in" accounts,  not the other 1500 user accounts in that domain.

Any idea how to resolve this?  

Thanks!

0
Comment
Question by:teex-nis
6 Comments
 
LVL 6

Expert Comment

by:sharjeel ashraf
ID: 34985330
did you create teh trusts manually, i.e. on domain first then the other, or did you use the wizard in 2008 and tell the wizard to create the trust on the other side.

also are you using the same account on both servers.

0
 
LVL 37

Expert Comment

by:Neil Russell
ID: 34986244
First of all, there is no such thing as a PDC!  PDC's died with NT Server 4.0 Now ALL domain controllers are domain controllers. Not Backup domain controllers or PDC's Just domain controllers.

You said in your post "But on any other member server or other domain controllers in Forest A"
Are you saying you have a Multi domain forest in A? Is your issue with servers in another domain in the same forest as the server you created the trust or the same domain? Your text here is a little ambiguos thats all.
0
 

Author Comment

by:teex-nis
ID: 34997794
The trust was created using the wizard in 2008.

There is only one domain in each forest.

Things are working fine from domain B (the windows 2003 domain).  but in domain A, only the first domain controller in that domain can see accounts from Domain B.  None of the other domain controllers or member servers in the 2008 domain can see user objects from the 2003 domain.

Thanks
0
 

Accepted Solution

by:
teex-nis earned 0 total points
ID: 35010819
Found the problem,  some how the trust had stopped working.  

I removed the trust and re-created it and things are working fine now.  thanks!
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 35399161
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question