Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Fixing Failed Forest Trust

Posted on 2011-03-04
5
Medium Priority
?
2,968 Views
Last Modified: 2012-05-11
I have two forests/domains that used to have a successful trust between them. Years ago, Domain B had their domain controller replaced as it was failing. The bad one was not demoted, so the switch was not proper. After this is around when someone noticed the trust failed. Now, years later, I'm tasked with fixing the trust but I cannot seem to find any information on the errors I get.

When I run the trust verification using the GUI tool for Active Directory, it fails due to the SC. When I looked this up, it was suggested that I use the netdom trust application to fix the trust. However when I run this command on either domain controller, it fails... but with different errors.

DomainA - Windows 2008 R2 DC:
C:\Windows\system32>netdom trust domainA.local /domain:domainB.local /
userd:domainA\admin /passwordd:* /usero:domainB\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

The specified network name is no longer available.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window


DomainB - Windows Server 2003 DC:
C:\Windows\system32>netdom trust domainB.local /domain:domainA.local /
userd:domainB\admin /passwordd:* /usero:domainA\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

Access is denied.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window

Both commands are running under an account with Domain Admin, Enterprise Admin and Schema Admin rights.

Any ideas?
0
Comment
Question by:_valkyrie_
  • 4
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35040049
Was that "bad DC" cleaned using metadata cleanup  http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Did it hold any FSMO roles?

Thanks

Mike
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040055
It held all the FSMO roles at the time. Someone moved three from Active Directory's GUI but the other two I only just moved forcefully using the command line tools.

The metadata cleanup was not run. I will try that out.
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040076
Also the GUI error that I get when resetting the trusts is:

DomainA
The outgoing trust was successfully validated.

The secure channel (SC) verification on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

Open in new window


DomainB
The secure channel (SC) verification on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The incoming trust was successfully validated.

Open in new window

0
 
LVL 2

Accepted Solution

by:
_valkyrie_ earned 0 total points
ID: 35040092
I ran the metadata cleanup but it only listed the current server, the old one didn't show up.
0
 
LVL 2

Author Closing Comment

by:_valkyrie_
ID: 35170835
Since no one else is offering ideas, I'm going to close this question. Problem still isn't resolved.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

877 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question