Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

windows 2003 AD issues

Posted on 2014-04-22
5
Medium Priority
?
207 Views
Last Modified: 2014-06-04
users not able to log into the DC.
when i perfom a netdiag i see an entry of
kerberos authentication failed
please advise?
when a user attempts to login we get a message of a trust relationship issue?
0
Comment
Question by:schuitkds
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 

Author Comment

by:schuitkds
ID: 40015797
also get some messages stating
Naming information cannot be located  --- the server is not operational
0
 
LVL 83

Expert Comment

by:David Johnson, CD, MVP
ID: 40016170
kerebos errors usually have to do with time being off between the client and the server (>15 Minutes Difference)
0
 
LVL 14

Accepted Solution

by:
Raj-GT earned 1500 total points
ID: 40017554
As David mentioned, it is usually caused by timing issues. Check the time and more importantly the timezone settings on your server and clients.
0
 

Author Comment

by:schuitkds
ID: 40018883
now i get an error message of
Windows cannot create the object <user> because: The directory service was unable to allocate a relative identifier.
I know this was a replication issue
I had 2 DC's  
I had to power off the second DC and do a system state restore to the Primary DC to reestablish the objects in AD.

can i wipe out the reference to the secondary AD and make the system think it has only the Primary DC and establish full functionality. If so how?  
 If i can i would reformat the secondary DC and reinstall the OS and rejoin to domain and once again make it DC at that point.

If i can not wipe out the secondary DC, how do i force the secondary DC to accept replication from the primary DC alone ( one way replication)  and block the replication of the secondary DC info up to the primary DC.
i believe the secondary DC may have been faulty and pushed old AD info up to the primary DC which initiated all the issues.
Thanks in advance
0
 
LVL 14

Expert Comment

by:Raj-GT
ID: 40019298
Have you transferred all the FSMO roles to this dc?
0

Featured Post

Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Learn about cloud computing and its benefits for small business owners.
This video Micro Tutorial explains how to clone a hard drive using a commercial software product for Windows systems called Casper from Future Systems Solutions (FSS). Cloning makes an exact, complete copy of one hard disk drive (HDD) onto another d…
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question