Solved

Fixing Failed Forest Trust

Posted on 2011-03-04
5
2,717 Views
Last Modified: 2012-05-11
I have two forests/domains that used to have a successful trust between them. Years ago, Domain B had their domain controller replaced as it was failing. The bad one was not demoted, so the switch was not proper. After this is around when someone noticed the trust failed. Now, years later, I'm tasked with fixing the trust but I cannot seem to find any information on the errors I get.

When I run the trust verification using the GUI tool for Active Directory, it fails due to the SC. When I looked this up, it was suggested that I use the netdom trust application to fix the trust. However when I run this command on either domain controller, it fails... but with different errors.

DomainA - Windows 2008 R2 DC:
C:\Windows\system32>netdom trust domainA.local /domain:domainB.local /
userd:domainA\admin /passwordd:* /usero:domainB\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

The specified network name is no longer available.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window


DomainB - Windows Server 2003 DC:
C:\Windows\system32>netdom trust domainB.local /domain:domainA.local /
userd:domainB\admin /passwordd:* /usero:domainA\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

Access is denied.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window

Both commands are running under an account with Domain Admin, Enterprise Admin and Schema Admin rights.

Any ideas?
0
Comment
Question by:_valkyrie_
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35040049
Was that "bad DC" cleaned using metadata cleanup  http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Did it hold any FSMO roles?

Thanks

Mike
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040055
It held all the FSMO roles at the time. Someone moved three from Active Directory's GUI but the other two I only just moved forcefully using the command line tools.

The metadata cleanup was not run. I will try that out.
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040076
Also the GUI error that I get when resetting the trusts is:

DomainA
The outgoing trust was successfully validated.

The secure channel (SC) verification on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

Open in new window


DomainB
The secure channel (SC) verification on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The incoming trust was successfully validated.

Open in new window

0
 
LVL 2

Accepted Solution

by:
_valkyrie_ earned 0 total points
ID: 35040092
I ran the metadata cleanup but it only listed the current server, the old one didn't show up.
0
 
LVL 2

Author Closing Comment

by:_valkyrie_
ID: 35170835
Since no one else is offering ideas, I'm going to close this question. Problem still isn't resolved.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question