Re: How do I reestablish a trust relationship?

From: Greg Brown (greg@socal_dot_rr.com)
Date: 07/30/02


From: "Greg Brown" <greg@socal_dot_rr.com>
Date: Tue, 30 Jul 2002 08:17:48 -0700


1. Remove the server from the domain and make it a stand alone machine.
Make sure you know the local administrator password.
2. Delete the machine account from the domain.
3. Add the server back to the domain.

Regards,
Greg

"David Gressett" <gressett@airmail.net> wrote in message
news:6EC90F20284B3371.0E0764E50C2C269F.761111B4E64DD2E1@lp.airnews.net...
> I am stopped midstream in the process of replacing a Windows 2000
> server with a new one. The old server was installed and configured
> with a variety of options that I need to do differently now, and has
> developed some problems that have no obvious causes, so I didn't want
> to just restore a backup of the old system onto the new (identical)
> hardware.I tried to install my Windows server and application software
> on the new hardware. This worked just fine. I recreated all the user
> accounts with no problems. The grief started when the workstations
> tried to log in. The Event Viewer on the new server was collecting
> error messages like this:
>
> "The computer STRAWBERRY tried to connect to the server \\PISTACHIO
> using the trust relationship established by the APPA domain. However,
> the computer lost the correct Security Identifier (SID) when the
> domain was reconfigured. Reestablish the trust relationship.
>
> How do I do that?



Relevant Pages

  • Re: Windows event id 4 (kerberos)
    ... I verified SPNs and computer names - No duplication found. ... if you would explain what is going here with examples of server names based on description that would be great. ... computer account automatically updates its machine account password in ... The target name used was ...
    (comp.protocols.kerberos)
  • Re: adding another domain controller problem
    ... Failed to modify the necessary properties for the machine account ... When you run Dcpromo to create a replica domain controller, ... When one or more domain controllers are on a Windows 2000 server that is ... Failed to modify the necessary properties> for>> the machine account server2$ Access is denied. ...
    (microsoft.public.windows.server.networking)
  • RE: LAN_SENDER_ERROR 576 When trying to Install a Secondary Site Serve
    ... I also added another Domain Controller with Windows 2003 R2 Machine account ... to the Domain Admins performed the same test and this fails. ... So in summary my PS Server is a member server with windows 2003 release 2 ... I have also tested this with just 2 workstations and with workstation 1's ...
    (microsoft.public.sms.setup)
  • Re: Member server rejoining domain
    ... The restore process is suppose to maintain the SID however it is going to ... member server is removed from the domain and then you have to rejoin it ... At this point the old server is no longer on the domain. ... Do I have to delete the leftover machine account from the old ...
    (microsoft.public.windows.server.active_directory)
  • Re: Changing domain user password
    ... find the machine account and open its properties. ... There should be Delegation tab where you can enable it. ... If you put this off until your 2003 server upgrade, ... >> configure the machine account for the web server for Kerberos Delegation ...
    (microsoft.public.dotnet.framework.aspnet.security)