Child Domain Problems


hi. have windows 2003 server (all sp2), based forest 1 parent , 1 child domain set up. there 2 dc servers global catalogs (gc) in parent domain, , 1 dc/gc in child domain. within ad sites , services can replicate on parent domain (between parent servers) via default-first-site-name/servers/ntds not child domain parent servers. these events, 40960 (lsasrv) logged periodically:
the security system detected authentication error server ldap/dc_server.child.domain.com/child.domain.com@child.domain.com. failure code authentication protocol kerberos "there no logon servers available service logon request.(0xc000005e)".

using 'netdiag' on dc in each domain, results marked 'passed'. using 'dcdiag', (everything after passes):

 testing server: default-first-site-name\dc_server
    starting test: connectivity
       ......................... dc_server passed test connectivity

ing primary tests

 testing server: default-first-site-name\dc_server
    starting test: replications
       [parent_dc] dsbindwithspnex() failed error -2146892976,
       system detected possible attempt compromise security.  please
sure can contact server authenticated you..
       [parent2_dc] dsbindwithspnex() failed error -2146892976,
       system detected possible attempt compromise security.  please
sure can contact server authenticated you..
       ......................... dc_server passed test replications
    starting test: ncsecdesc
       ......................... dc_server passed test ncsecdesc
    starting test: netlogons
       ......................... dc_server passed test netlogons
    starting test: advertising
       ......................... dc_server passed test advertising
    starting test: knowsofroleholders
       warning: parent_dc schema owner, not responding ds rpc bind
         [parent_dc] ldap bind failed error 8341,
         directory service error has occurred..
         warning: parent_dc schema owner, not responding ldap bind.

         warning: parent_dc domain owner, not responding ds rpc bin
d.
         warning: parent_dc domain owner, not responding ldap bind.

this article (http://support.microsoft.com/kb/824217) not offer resolution.
there no antivirus/firewall on servers. time on servers synchronized within 1 minute.
tia help,

dave


sf dave

 

hi,

 

based on research, problem might caused trust relationship between parent , child has been corrupted. please run following command on root domain controllers of parent domain , of child domain test result.

 

this command resets trust relationship between parent , child domain.

 

netdom trust trusting_domain_name /domain:trusted_domain_name /userd:user /passwordd:* /usero:user /passwordo:* /reset

 

more information, please refer to:

 

windows server 2003-based domain controllers in parent-and-child domain environment may unable replicate changes

 

http://support.microsoft.com/kb/938702/en-us

 

please perform steps above see how replication going. if need further assistance, please post back.

 

 

best wishes

--------------
morgan che



Windows Server  >  Directory Services



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

difference between wuauclt1.exe and wuauclt.exe

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL