Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , , ,

Sponsored Links



Trust relationship failing between 2003 and 2000 servers

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 07-01-2005
climberpm
 
Posts: n/a
Trust relationship failing between 2003 and 2000 servers

I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was
having some issues with Front Page where users couldn't logon using domain
user accounts so I popped the hood, so to speak.
Netdiag says the following:
DC discovery test. . . . . . . . . : Passed
DC list test . . . . . . . . . . . : Failed
'ONLINE': No DCs are up.
Trust relationship test. . . . . . : Failed
'ONLINE': No DCs are up (Cannot run test).
[FATAL] Secure channel to domain 'ONLINE' is broken.
[ERROR_NO_LOGON_SERVERS]
Kerberos test. . . . . . . . . . . : Failed
[FATAL] Kerberos does not have a ticket for
host/ptdata25.online.2000.
LDAP test. . . . . . . . . . . . . : Passed
[WARNING] Failed to query SPN registration on DC 'onlinedc.online.2000'.
[WARNING] Failed to query SPN registration on DC
'onlinedc2.online.2000'.

The 2003 servers were able to join the 200 domain without incident and I can
logon locally as a 2000 domain administrator.
The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to
work fine with this DNS server
However when I try to ping the DC by name I get :
C:\Program Files\Support Tools>ping onlinedc.online.2000
Ping request could not find host onlinedc.online.2000. Please check the name
and
try again.

If I ping by IP it's OK or if a do a ping -a it responds with the correct
name.

I can add domain user acounts to a resource and they appear correctly but
when I click OK or apply the names change to SIDs. Ultimately I cannot
access resources using domain accounts.

Any thoughts ?

Thanks

Paul


Reply With Quote
  #2  
Old 07-01-2005
Glenn L
 
Posts: n/a
Re: Trust relationship failing between 2003 and 2000 servers

Have you attempted to reset the secure channel?
NLTEST /SC_RESET:FQDNofdomain


--
Glenn L
CCNA, MCSE 2000/2003 + Security

"climberpm" <hostmaster@online2000.net> wrote in message
news:ywkDd.34707$NC6.26143@newsread1.mlpsca01.us.to.verio.net...
>I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was
>having some issues with Front Page where users couldn't logon using domain
>user accounts so I popped the hood, so to speak.
> Netdiag says the following:
> DC discovery test. . . . . . . . . : Passed
> DC list test . . . . . . . . . . . : Failed
> 'ONLINE': No DCs are up.
> Trust relationship test. . . . . . : Failed
> 'ONLINE': No DCs are up (Cannot run test).
> [FATAL] Secure channel to domain 'ONLINE' is broken.
> [ERROR_NO_LOGON_SERVERS]
> Kerberos test. . . . . . . . . . . : Failed
> [FATAL] Kerberos does not have a ticket for
> host/ptdata25.online.2000.
> LDAP test. . . . . . . . . . . . . : Passed
> [WARNING] Failed to query SPN registration on DC
> 'onlinedc.online.2000'.
> [WARNING] Failed to query SPN registration on DC
> 'onlinedc2.online.2000'.
>
> The 2003 servers were able to join the 200 domain without incident and I
> can logon locally as a 2000 domain administrator.
> The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to
> work fine with this DNS server
> However when I try to ping the DC by name I get :
> C:\Program Files\Support Tools>ping onlinedc.online.2000
> Ping request could not find host onlinedc.online.2000. Please check the
> name and
> try again.
>
> If I ping by IP it's OK or if a do a ping -a it responds with the correct
> name.
>
> I can add domain user acounts to a resource and they appear correctly but
> when I click OK or apply the names change to SIDs. Ultimately I cannot
> access resources using domain accounts.
>
> Any thoughts ?
>
> Thanks
>
> Paul
>



Reply With Quote
  #3  
Old 07-01-2005
Glenn L
 
Posts: n/a
Re: Trust relationship failing between 2003 and 2000 servers

Have you attempted to reset the secure channel?
NLTEST /SC_RESET:FQDNofdomain


--
Glenn L
CCNA, MCSE 2000/2003 + Security

"climberpm" <hostmaster@online2000.net> wrote in message
news:ywkDd.34707$NC6.26143@newsread1.mlpsca01.us.to.verio.net...
>I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was
>having some issues with Front Page where users couldn't logon using domain
>user accounts so I popped the hood, so to speak.
> Netdiag says the following:
> DC discovery test. . . . . . . . . : Passed
> DC list test . . . . . . . . . . . : Failed
> 'ONLINE': No DCs are up.
> Trust relationship test. . . . . . : Failed
> 'ONLINE': No DCs are up (Cannot run test).
> [FATAL] Secure channel to domain 'ONLINE' is broken.
> [ERROR_NO_LOGON_SERVERS]
> Kerberos test. . . . . . . . . . . : Failed
> [FATAL] Kerberos does not have a ticket for
> host/ptdata25.online.2000.
> LDAP test. . . . . . . . . . . . . : Passed
> [WARNING] Failed to query SPN registration on DC
> 'onlinedc.online.2000'.
> [WARNING] Failed to query SPN registration on DC
> 'onlinedc2.online.2000'.
>
> The 2003 servers were able to join the 200 domain without incident and I
> can logon locally as a 2000 domain administrator.
> The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to
> work fine with this DNS server
> However when I try to ping the DC by name I get :
> C:\Program Files\Support Tools>ping onlinedc.online.2000
> Ping request could not find host onlinedc.online.2000. Please check the
> name and
> try again.
>
> If I ping by IP it's OK or if a do a ping -a it responds with the correct
> name.
>
> I can add domain user acounts to a resource and they appear correctly but
> when I click OK or apply the names change to SIDs. Ultimately I cannot
> access resources using domain accounts.
>
> Any thoughts ?
>
> Thanks
>
> Paul
>



Reply With Quote
  #4  
Old 07-01-2005
Glenn L
 
Posts: n/a
Re: Trust relationship failing between 2003 and 2000 servers

Have you attempted to reset the secure channel?
NLTEST /SC_RESET:FQDNofdomain


--
Glenn L
CCNA, MCSE 2000/2003 + Security

"climberpm" <hostmaster@online2000.net> wrote in message
news:ywkDd.34707$NC6.26143@newsread1.mlpsca01.us.to.verio.net...
>I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was
>having some issues with Front Page where users couldn't logon using domain
>user accounts so I popped the hood, so to speak.
> Netdiag says the following:
> DC discovery test. . . . . . . . . : Passed
> DC list test . . . . . . . . . . . : Failed
> 'ONLINE': No DCs are up.
> Trust relationship test. . . . . . : Failed
> 'ONLINE': No DCs are up (Cannot run test).
> [FATAL] Secure channel to domain 'ONLINE' is broken.
> [ERROR_NO_LOGON_SERVERS]
> Kerberos test. . . . . . . . . . . : Failed
> [FATAL] Kerberos does not have a ticket for
> host/ptdata25.online.2000.
> LDAP test. . . . . . . . . . . . . : Passed
> [WARNING] Failed to query SPN registration on DC
> 'onlinedc.online.2000'.
> [WARNING] Failed to query SPN registration on DC
> 'onlinedc2.online.2000'.
>
> The 2003 servers were able to join the 200 domain without incident and I
> can logon locally as a 2000 domain administrator.
> The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to
> work fine with this DNS server
> However when I try to ping the DC by name I get :
> C:\Program Files\Support Tools>ping onlinedc.online.2000
> Ping request could not find host onlinedc.online.2000. Please check the
> name and
> try again.
>
> If I ping by IP it's OK or if a do a ping -a it responds with the correct
> name.
>
> I can add domain user acounts to a resource and they appear correctly but
> when I click OK or apply the names change to SIDs. Ultimately I cannot
> access resources using domain accounts.
>
> Any thoughts ?
>
> Thanks
>
> Paul
>



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Trust relationship failing between 2003 and 2000 servers"
Thread Thread Starter Forum Replies Last Post
Trust relationship Windows 2003 Rush Active Directory 1 11-06-2010 12:48 PM
Win 2000 / 2003, trust / ad / dns error rayten Active Directory 1 03-02-2010 01:08 PM
2000 DNS Servers in 2003 AD Domain Chris U Windows Server Help 5 17-12-2008 07:00 PM
Creating a two-way Trust between Windows 2003 and 2000 mbartosh Windows Server Help 1 09-11-2008 06:42 PM
add trust relationship between NT4 and Windows 2003 Domains nobigworld@gmail.com Windows Server Help 3 21-11-2005 12:38 PM


All times are GMT +5.5. The time now is 12:44 PM.