Solved

Fixing Failed Forest Trust

Posted on 2011-03-04
5
2,762 Views
Last Modified: 2012-05-11
I have two forests/domains that used to have a successful trust between them. Years ago, Domain B had their domain controller replaced as it was failing. The bad one was not demoted, so the switch was not proper. After this is around when someone noticed the trust failed. Now, years later, I'm tasked with fixing the trust but I cannot seem to find any information on the errors I get.

When I run the trust verification using the GUI tool for Active Directory, it fails due to the SC. When I looked this up, it was suggested that I use the netdom trust application to fix the trust. However when I run this command on either domain controller, it fails... but with different errors.

DomainA - Windows 2008 R2 DC:
C:\Windows\system32>netdom trust domainA.local /domain:domainB.local /
userd:domainA\admin /passwordd:* /usero:domainB\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

The specified network name is no longer available.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window


DomainB - Windows Server 2003 DC:
C:\Windows\system32>netdom trust domainB.local /domain:domainA.local /
userd:domainB\admin /passwordd:* /usero:domainA\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

Access is denied.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window

Both commands are running under an account with Domain Admin, Enterprise Admin and Schema Admin rights.

Any ideas?
0
Comment
Question by:_valkyrie_
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35040049
Was that "bad DC" cleaned using metadata cleanup  http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Did it hold any FSMO roles?

Thanks

Mike
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040055
It held all the FSMO roles at the time. Someone moved three from Active Directory's GUI but the other two I only just moved forcefully using the command line tools.

The metadata cleanup was not run. I will try that out.
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040076
Also the GUI error that I get when resetting the trusts is:

DomainA
The outgoing trust was successfully validated.

The secure channel (SC) verification on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

Open in new window


DomainB
The secure channel (SC) verification on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The incoming trust was successfully validated.

Open in new window

0
 
LVL 2

Accepted Solution

by:
_valkyrie_ earned 0 total points
ID: 35040092
I ran the metadata cleanup but it only listed the current server, the old one didn't show up.
0
 
LVL 2

Author Closing Comment

by:_valkyrie_
ID: 35170835
Since no one else is offering ideas, I'm going to close this question. Problem still isn't resolved.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question