Expiring Today—Celebrate National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Domain trust

Posted on 2013-05-22
5
Medium Priority
?
696 Views
Last Modified: 2013-05-24
I have 2 domains.

One is very old, one is new. (Building a trust between new and old)
The new one was built with a cloned machine, yup a bad thing.

I created a fresh install (2008 server), dcpromo into the new domain, dcpromo the cloned controller out (2008)
Verified sids.

SID for \\NEWDOMAIN-DC2:
S-1-5-21-1120723719-3465974444-2764455207

SID for PRODIE\NEWDOMAIN-dc2$:
S-1-5-21-1120723719-3465974444-2764455207-1157


SID for \\OLDDOMAIN-dc:
S-1-5-21-683549635-711648030-2797980900

SID for STEELCRAFT\OLDDOMAIN-dc$:
S-1-5-21-683549635-711648030-2797980900-1478

I am trying to build a trust between these two domains. I still get "domain trust cannot create a file when that file already exists"

I have gone through DNS to make sure there are no phantom entries
I have used netdom to check the trust and trusts that exsist.

I am stuck
The only thing I can think of is that the domain name itself is exactly the same.
0
Comment
Question by:wlacroix
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 3

Author Comment

by:wlacroix
ID: 39189020
Rename of the domain wont save me, it leaves the SID in tact and does not affect trust relationships.
0
 
LVL 3

Author Comment

by:wlacroix
ID: 39189147
So far the only thing I can see is it is the DOMAIN sid not the machine sid.
0
 
LVL 26

Accepted Solution

by:
Leon Fester earned 1500 total points
ID: 39191140
This link explains the why it's broken.
http://support.microsoft.com/kb/127911

The new one was built with a cloned machine,
Where was it cloned from?

You could try deleting all the existing trusts and then rebuilding them from scratch.
0
 
LVL 3

Author Comment

by:wlacroix
ID: 39191688
I can verify that this was NOT the case because I built them myself.

2008 was built (no sysprep), then cloned, new controller added to domain 1, this server was promoted as the role holder and the forest was upgraded.


A new Clone was created from the 2008 build, this was built into a new domain with a different name. The trust never worked, it gave me the same error. (assumption here is SID error because of the clone situation)


SO....

New clone from the 2008 build (sysprep added), promoted to a domain controller in domain 2, demote the old one as stated above. you can clearly see the sids are NOT the same.
The only one that is left is the domain SID. (assumption here is that the domain was created with the bad cloned controller, pushing its information into the domain SID, so no matter what you do the sid is what it is, even a domain rename wont fix it, the sid wont change ever ever ever)



I am currently building a full new domain, domain 3, new domain name, new domain controllers everything. I suspect 2 things.

#1 the new domain will work, there is a new name, new netbios, new everything.
#2 the new domain will not work, its built off the EXACT same clone all the others were built off of. (on a side note i have 40 other servers built off the same clone)

SID for PD\newdomain3-dc$:
S-1-5-21-1944535435-2331424502-2653671940-1000

SID for \\newdomain3-dc:
S-1-5-21-1944535435-2331424502-2653671940

This domain name was reused when the new build happened, that could be it. I just cant see the domains having the same SID.
Any way to pull the domain SID itself, or is this a security breach?
0
 
LVL 3

Author Comment

by:wlacroix
ID: 39194387
New domain in place and all is ok so far, gong to use ADMT to try and move a computer.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
Resolving an irritating Remote Desktop connection that stops your saved credentials from being used.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question