Problem with domain trust after W2003SP1 upgrade

From: Stefan Cuypers (stefan.cuypers_at_nospam.postalias)
Date: 04/11/05

  • Next message: ben: "how to list remote NT service"
    Date: Mon, 11 Apr 2005 17:20:27 +0200
    
    

    I just upgraded the server on my domain with Windows 2003 SP1 and I'm
    experiencing problems with trust relationships. Does anyone have an idea
    what could be wrong here?

    Here's the situation:
    - my domain: cc.local, Windows 2003 native domain and Windows 2003 native
    forest, 1 AD server W2003 SP1
    - trusted domain: qualiphar.local, Windows 2003 native domain and Windows
    2000 forest (has another domain in it that is still at Windows 2000 level),
    2 AD server with W2003 (no SP1 yet)

    Since installing SP1 on my server, the event log reports 5719 event id's on
    the trust (see below).

    I then tried to remove the trust and recreate it.
    When recreating it from the cc.local domain controller it tells me: The
    operation failed. The error is: Unspecified error.

    When creating it from a qualiphar.local domain controller, the trust seems
    to create all right, but at the end a message says:
    "The verification of the incoming trust failed with the following error(s):
    The trust password verification test was inconclusive.
    A secure channel reset will be attempted.
    The secure channel reset failed with error 1727: The remote procedure call
    failed and did not execute.

    The outgoing trust has been verified. It is in place and active.
    "

    If I validate the trust later on, I get the same error.

    Event Type: Error
    Event Source: NETLOGON
    Event Category: None
    Event ID: 5719
    Date: 11/04/2005
    Time: 14:31:25
    User: N/A
    Computer: SCC-SRV1
    Description:
    This computer was not able to set up a secure session with a domain
    controller in domain QUALIPHAR due to the following:
    The remote procedure call failed and did not execute.
    This may lead to authentication problems. Make sure that this computer is
    connected to the network. If the problem persists, please contact your
    domain administrator.

    ADDITIONAL INFO
    If this computer is a domain controller for the specified domain, it sets up
    the secure session to the primary domain controller emulator in the
    specified domain. Otherwise, this computer sets up the secure session to any
    domain controller in the specified domain.

    For more information, see Help and Support Center at
    http://go.microsoft.com/fwlink/events.asp.
    Data:
    0000: 1c 00 02 c0 ...À

    regards,
    Stefan Cuypers


  • Next message: ben: "how to list remote NT service"

    Relevant Pages

    • RE: Trust Domain from W2k3 to W2k
      ... How to establish trusts with a Windows NT-based domain in Windows Server ... add the name on the correct box on the Trust Tab. ... Please reconfirm the computer account was enabled. ... The DNS suffix of the computer name of a new domain controller may not ...
      (microsoft.public.windows.server.migration)
    • RE: How to create trust relationship between Windows 2003 Server (domain controler) and Windows NT 4
      ... relationship between windows NT and Windows 2003 by following the ... Establish Trusts with a Windows NT-Based Domain in Windows Server ... How to Create a Trust Relationship ... Create a Two-Way Trust Relationship ...
      (microsoft.public.win2000.security)
    • Re: How to connect the NT4 PCD from windows 2003 server
      ... the NT domain and in the properties of the trust for incoming and outgoing ... I would also go into Domain Controller Security ... When you create lmhosts file make sure ... You can also use nbtstat -c on the Windows ...
      (microsoft.public.win2000.security)
    • 2003 to NT Domain Trust not working.
      ... the Windows 2000 domain. ... PDC tries to create a trust. ... The domain contains an NT Server 4.0 PDC, ... dom2K domain controllers. ...
      (microsoft.public.win2000.networking)
    • Re: Trust windows 2k to windows 2k3
      ... only reply to Newsgroups ... Having the trust running is the first step. ... it seems to validate outbound from my Windows ... On the 2000 create a secondary zone, correct, on the 2003 you ...
      (microsoft.public.windows.server.active_directory)