Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Fixing Failed Forest Trust

Posted on 2011-03-04
5
Medium Priority
?
2,862 Views
Last Modified: 2012-05-11
I have two forests/domains that used to have a successful trust between them. Years ago, Domain B had their domain controller replaced as it was failing. The bad one was not demoted, so the switch was not proper. After this is around when someone noticed the trust failed. Now, years later, I'm tasked with fixing the trust but I cannot seem to find any information on the errors I get.

When I run the trust verification using the GUI tool for Active Directory, it fails due to the SC. When I looked this up, it was suggested that I use the netdom trust application to fix the trust. However when I run this command on either domain controller, it fails... but with different errors.

DomainA - Windows 2008 R2 DC:
C:\Windows\system32>netdom trust domainA.local /domain:domainB.local /
userd:domainA\admin /passwordd:* /usero:domainB\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

The specified network name is no longer available.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window


DomainB - Windows Server 2003 DC:
C:\Windows\system32>netdom trust domainB.local /domain:domainA.local /
userd:domainB\admin /passwordd:* /usero:domainA\admin /passwordo
:* /reset /twoway
Type the password associated with the domain user:

Type the password associated with the object user:

Access is denied.

The command failed to complete successfully.


C:\Windows\system32>

Open in new window

Both commands are running under an account with Domain Admin, Enterprise Admin and Schema Admin rights.

Any ideas?
0
Comment
Question by:_valkyrie_
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 35040049
Was that "bad DC" cleaned using metadata cleanup  http://www.petri.co.il/delete_failed_dcs_from_ad.htm

Did it hold any FSMO roles?

Thanks

Mike
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040055
It held all the FSMO roles at the time. Someone moved three from Active Directory's GUI but the other two I only just moved forcefully using the command line tools.

The metadata cleanup was not run. I will try that out.
0
 
LVL 2

Author Comment

by:_valkyrie_
ID: 35040076
Also the GUI error that I get when resetting the trusts is:

DomainA
The outgoing trust was successfully validated.

The secure channel (SC) verification on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on Active Directory Domain Controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

Open in new window


DomainB
The secure channel (SC) verification on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The secure channel (SC) reset on domain controller \\DC.domainB.local of domain domainB.local to domain domainA.local failed with error: Access is denied.

The incoming trust was successfully validated.

Open in new window

0
 
LVL 2

Accepted Solution

by:
_valkyrie_ earned 0 total points
ID: 35040092
I ran the metadata cleanup but it only listed the current server, the old one didn't show up.
0
 
LVL 2

Author Closing Comment

by:_valkyrie_
ID: 35170835
Since no one else is offering ideas, I'm going to close this question. Problem still isn't resolved.
0

Featured Post

Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question