|
| |||||||||
| Tags: 2000, 2003, failing, relationship, servers, trust |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Trust relationship failing between 2003 and 2000 servers
I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was having some issues with Front Page where users couldn't logon using domain user accounts so I popped the hood, so to speak. Netdiag says the following: DC discovery test. . . . . . . . . : Passed DC list test . . . . . . . . . . . : Failed 'ONLINE': No DCs are up. Trust relationship test. . . . . . : Failed 'ONLINE': No DCs are up (Cannot run test). [FATAL] Secure channel to domain 'ONLINE' is broken. [ERROR_NO_LOGON_SERVERS] Kerberos test. . . . . . . . . . . : Failed [FATAL] Kerberos does not have a ticket for host/ptdata25.online.2000. LDAP test. . . . . . . . . . . . . : Passed [WARNING] Failed to query SPN registration on DC 'onlinedc.online.2000'. [WARNING] Failed to query SPN registration on DC 'onlinedc2.online.2000'. The 2003 servers were able to join the 200 domain without incident and I can logon locally as a 2000 domain administrator. The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to work fine with this DNS server However when I try to ping the DC by name I get : C:\Program Files\Support Tools>ping onlinedc.online.2000 Ping request could not find host onlinedc.online.2000. Please check the name and try again. If I ping by IP it's OK or if a do a ping -a it responds with the correct name. I can add domain user acounts to a resource and they appear correctly but when I click OK or apply the names change to SIDs. Ultimately I cannot access resources using domain accounts. Any thoughts ? Thanks Paul |
|
#2
| |||
| |||
| Re: Trust relationship failing between 2003 and 2000 servers
Have you attempted to reset the secure channel? NLTEST /SC_RESET:FQDNofdomain -- Glenn L CCNA, MCSE 2000/2003 + Security "climberpm" <hostmaster@online2000.net> wrote in message news:ywkDd.34707$NC6.26143@newsread1.mlpsca01.us.to.verio.net... >I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was >having some issues with Front Page where users couldn't logon using domain >user accounts so I popped the hood, so to speak. > Netdiag says the following: > DC discovery test. . . . . . . . . : Passed > DC list test . . . . . . . . . . . : Failed > 'ONLINE': No DCs are up. > Trust relationship test. . . . . . : Failed > 'ONLINE': No DCs are up (Cannot run test). > [FATAL] Secure channel to domain 'ONLINE' is broken. > [ERROR_NO_LOGON_SERVERS] > Kerberos test. . . . . . . . . . . : Failed > [FATAL] Kerberos does not have a ticket for > host/ptdata25.online.2000. > LDAP test. . . . . . . . . . . . . : Passed > [WARNING] Failed to query SPN registration on DC > 'onlinedc.online.2000'. > [WARNING] Failed to query SPN registration on DC > 'onlinedc2.online.2000'. > > The 2003 servers were able to join the 200 domain without incident and I > can logon locally as a 2000 domain administrator. > The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to > work fine with this DNS server > However when I try to ping the DC by name I get : > C:\Program Files\Support Tools>ping onlinedc.online.2000 > Ping request could not find host onlinedc.online.2000. Please check the > name and > try again. > > If I ping by IP it's OK or if a do a ping -a it responds with the correct > name. > > I can add domain user acounts to a resource and they appear correctly but > when I click OK or apply the names change to SIDs. Ultimately I cannot > access resources using domain accounts. > > Any thoughts ? > > Thanks > > Paul > |
|
#3
| |||
| |||
| Re: Trust relationship failing between 2003 and 2000 servers
Have you attempted to reset the secure channel? NLTEST /SC_RESET:FQDNofdomain -- Glenn L CCNA, MCSE 2000/2003 + Security "climberpm" <hostmaster@online2000.net> wrote in message news:ywkDd.34707$NC6.26143@newsread1.mlpsca01.us.to.verio.net... >I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was >having some issues with Front Page where users couldn't logon using domain >user accounts so I popped the hood, so to speak. > Netdiag says the following: > DC discovery test. . . . . . . . . : Passed > DC list test . . . . . . . . . . . : Failed > 'ONLINE': No DCs are up. > Trust relationship test. . . . . . : Failed > 'ONLINE': No DCs are up (Cannot run test). > [FATAL] Secure channel to domain 'ONLINE' is broken. > [ERROR_NO_LOGON_SERVERS] > Kerberos test. . . . . . . . . . . : Failed > [FATAL] Kerberos does not have a ticket for > host/ptdata25.online.2000. > LDAP test. . . . . . . . . . . . . : Passed > [WARNING] Failed to query SPN registration on DC > 'onlinedc.online.2000'. > [WARNING] Failed to query SPN registration on DC > 'onlinedc2.online.2000'. > > The 2003 servers were able to join the 200 domain without incident and I > can logon locally as a 2000 domain administrator. > The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to > work fine with this DNS server > However when I try to ping the DC by name I get : > C:\Program Files\Support Tools>ping onlinedc.online.2000 > Ping request could not find host onlinedc.online.2000. Please check the > name and > try again. > > If I ping by IP it's OK or if a do a ping -a it responds with the correct > name. > > I can add domain user acounts to a resource and they appear correctly but > when I click OK or apply the names change to SIDs. Ultimately I cannot > access resources using domain accounts. > > Any thoughts ? > > Thanks > > Paul > |
|
#4
| |||
| |||
| Re: Trust relationship failing between 2003 and 2000 servers
Have you attempted to reset the secure channel? NLTEST /SC_RESET:FQDNofdomain -- Glenn L CCNA, MCSE 2000/2003 + Security "climberpm" <hostmaster@online2000.net> wrote in message news:ywkDd.34707$NC6.26143@newsread1.mlpsca01.us.to.verio.net... >I have 2 new Windows 2003 member servers in a Windows 2000 domain. I was >having some issues with Front Page where users couldn't logon using domain >user accounts so I popped the hood, so to speak. > Netdiag says the following: > DC discovery test. . . . . . . . . : Passed > DC list test . . . . . . . . . . . : Failed > 'ONLINE': No DCs are up. > Trust relationship test. . . . . . : Failed > 'ONLINE': No DCs are up (Cannot run test). > [FATAL] Secure channel to domain 'ONLINE' is broken. > [ERROR_NO_LOGON_SERVERS] > Kerberos test. . . . . . . . . . . : Failed > [FATAL] Kerberos does not have a ticket for > host/ptdata25.online.2000. > LDAP test. . . . . . . . . . . . . : Passed > [WARNING] Failed to query SPN registration on DC > 'onlinedc.online.2000'. > [WARNING] Failed to query SPN registration on DC > 'onlinedc2.online.2000'. > > The 2003 servers were able to join the 200 domain without incident and I > can logon locally as a 2000 domain administrator. > The 2003 servers use the 2000 DC as their DNS server and NSLookup seems to > work fine with this DNS server > However when I try to ping the DC by name I get : > C:\Program Files\Support Tools>ping onlinedc.online.2000 > Ping request could not find host onlinedc.online.2000. Please check the > name and > try again. > > If I ping by IP it's OK or if a do a ping -a it responds with the correct > name. > > I can add domain user acounts to a resource and they appear correctly but > when I click OK or apply the names change to SIDs. Ultimately I cannot > access resources using domain accounts. > > Any thoughts ? > > Thanks > > Paul > |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Trust relationship failing between 2003 and 2000 servers" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Trust relationship Windows 2003 | Rush | Active Directory | 1 | 11-06-2010 12:48 PM |
| Win 2000 / 2003, trust / ad / dns error | rayten | Active Directory | 1 | 03-02-2010 01:08 PM |
| 2000 DNS Servers in 2003 AD Domain | Chris U | Windows Server Help | 5 | 17-12-2008 07:00 PM |
| Creating a two-way Trust between Windows 2003 and 2000 | mbartosh | Windows Server Help | 1 | 09-11-2008 06:42 PM |
| add trust relationship between NT4 and Windows 2003 Domains | nobigworld@gmail.com | Windows Server Help | 3 | 21-11-2005 12:38 PM |