Child Domain Problems
the security system detected authentication error server ldap/dc_server.child.domain.com/child.domain.com@child.domain.com. failure code authentication protocol kerberos "there no logon servers available service logon request.(0xc000005e)".
using 'netdiag' on dc in each domain, results marked 'passed'. using 'dcdiag', (everything after passes):
testing server: default-first-site-name\dc_server
starting test: connectivity
......................... dc_server passed test connectivity
ing primary tests
testing server: default-first-site-name\dc_server
starting test: replications
[parent_dc] dsbindwithspnex() failed error -2146892976,
system detected possible attempt compromise security. please
sure can contact server authenticated you..
[parent2_dc] dsbindwithspnex() failed error -2146892976,
system detected possible attempt compromise security. please
sure can contact server authenticated you..
......................... dc_server passed test replications
starting test: ncsecdesc
......................... dc_server passed test ncsecdesc
starting test: netlogons
......................... dc_server passed test netlogons
starting test: advertising
......................... dc_server passed test advertising
starting test: knowsofroleholders
warning: parent_dc schema owner, not responding ds rpc bind
[parent_dc] ldap bind failed error 8341,
directory service error has occurred..
warning: parent_dc schema owner, not responding ldap bind.
warning: parent_dc domain owner, not responding ds rpc bin
d.
warning: parent_dc domain owner, not responding ldap bind.
this article (http://support.microsoft.com/kb/824217) not offer resolution.
there no antivirus/firewall on servers. time on servers synchronized within 1 minute.
tia help,
dave
sf dave
hi,
based on research, problem might caused trust relationship between parent , child has been corrupted. please run following command on root domain controllers of parent domain , of child domain test result.
this command resets trust relationship between parent , child domain.
netdom trust trusting_domain_name /domain:trusted_domain_name /userd:user /passwordd:* /usero:user /passwordo:* /reset
more information, please refer to:
windows server 2003-based domain controllers in parent-and-child domain environment may unable replicate changes
http://support.microsoft.com/kb/938702/en-us
please perform steps above see how replication going. if need further assistance, please post back.
best wishes
--------------
morgan che
Windows Server > Directory Services
Comments
Post a Comment