| Author |
Message |
Guest
|
Posted:
Fri Sep 30, 2005 12:50 am Post subject:
Trust relationship exists but still dc asks for authenticati |
|
|
Hi all,
I've spent the last two days trying to do a migration of users from a
windows 2003 domain to another windows 2003 domain using ADMTv2.
I prepared the trust relationships between both domains which are
created without errors. (Two-way, External).
But the behaviour is different depending on where I am testing it from:
From the source domain:
1) add the target_domain\Domain Admins group inside the Administrators
group of the source domain: WORKS OK.
And then, from the target domain:
2) doing the same as above: A window pops up asking me for
username/password before I am able to browse the objects of the other
domain (source).
(and it has to be provided with username/password of a source account.
Does not accept any target account, even when I had already done the
first step above and included target_domain\Domain Admins in the
source's Administrators group).
I tried the trust relationship using "runas /user:someone@otherdomain
cmd" in both domains and it seems to work Ok though.
I have also tried 'nlstest' and it reports no errors at all. The same
with netdom.exe.
Thanks a lot for reading all the way through here, and for any pointers
that can help me out. |
|
| Back to top |
|
 |
Vincent Xu [MSFT]
Guest
|
Posted:
Fri Sep 30, 2005 8:20 am Post subject:
RE: Trust relationship exists but still dc asks for authenti |
|
|
Hi ,
For your situation, I suspect the problem is caused by the trust. So I have
following suggestion:
1. Re-build the 2-way trust by folllowing the article as below:
325874 How to establish trusts with a Windows NT-based domain in Windows
Server
http://support.microsoft.com/?id=325874
2. Validate the trust on both domains after the trust is built.
3. Take a screen shot when it prompt for username and password. You may
send me the screen shot via v-xuwen@microsoft.com
Best regards,
Vincent Xu
Microsoft Online Partner Support
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
Business-Critical Phone Support (BCPS) provides you with technical phone
support at no charge during critical LAN outages or "business down"
situations. This benefit is available 24 hours a day, 7 days a week to all
Microsoft technology partners in the United States and Canada.
This and other support options are available here:
BCPS:
https://partner.microsoft.com/US/technicalsupport/supportoverview/40010469
Others: https://partner.microsoft.com/US/technicalsupport/supportoverview/
If you are outside the United States, please visit our International
Support page: http://support.microsoft.com/common/international.aspx.
Newsgroup Web Interface Upgrade
Please complete a one-time registration process on your first visit to the
Partner Portal beginning July 11, 2005 at 9 A.M. PST by entering the secure
code mspp2005 when prompted. This secure code will be valid for 6 months
after which you will need to update your registration by entering the new
secure code. We will post announcements in the newsgroups prior to
expiration. Once you have entered the secure code mspp2005 , you will be
able to update your profile and access the the partner newsgroups. Please
update your Favorites link to the newsgroups web page, your current link
will redirect until November 1, 2005.
Please post any comment, questions or concerns to the
microsoft.private.directaccess.partnerfeedback newsgroup. For more
information, please go to:
https://partner.microsoft.com/global/technicalsupport/registeredsupport/4001
4662
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
| Quote: | From: vandresv@gmail.com
Newsgroups: microsoft.public.windows.server.migration
Subject: Trust relationship exists but still dc asks for authentication
Date: 29 Sep 2005 15:30:36 -0700
Organization: http://groups.google.com
Lines: 33
Message-ID: <1128033036.777413.50360@g49g2000cwa.googlegroups.com
NNTP-Posting-Host: 206.248.85.155
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Trace: posting.google.com 1128033042 22576 127.0.0.1 (29 Sep 2005
22:30:42 GMT)
X-Complaints-To: groups-abuse@google.com
NNTP-Posting-Date: Thu, 29 Sep 2005 22:30:42 +0000 (UTC)
User-Agent: G2/0.2
X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.7.10) Gecko/20050716 Firefox/1.0.6,gzip(gfe),gzip(gfe)
Complaints-To: groups-abuse@google.com
Injection-Info: g49g2000cwa.googlegroups.com; posting-host=206.248.85.155;
posting-account=XEL8Yg0AAABoXOCSDX5t5EqSow57z_xz
Path:
TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfeed00.sul.t-online.de!t-onli |
ne.de!border2.nntp.dca.giganews.com!nntp.giganews.com!postnews.google.com!g4
9g2000cwa.googlegroups.com!not-for-mail
| Quote: | Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:12174
X-Tomcat-NG: microsoft.public.windows.server.migration
Hi all,
I've spent the last two days trying to do a migration of users from a
windows 2003 domain to another windows 2003 domain using ADMTv2.
I prepared the trust relationships between both domains which are
created without errors. (Two-way, External).
But the behaviour is different depending on where I am testing it from:
From the source domain:
1) add the target_domain\Domain Admins group inside the Administrators
group of the source domain: WORKS OK.
And then, from the target domain:
2) doing the same as above: A window pops up asking me for
username/password before I am able to browse the objects of the other
domain (source).
(and it has to be provided with username/password of a source account.
Does not accept any target account, even when I had already done the
first step above and included target_domain\Domain Admins in the
source's Administrators group).
I tried the trust relationship using "runas /user:someone@otherdomain
cmd" in both domains and it seems to work Ok though.
I have also tried 'nlstest' and it reports no errors at all. The same
with netdom.exe.
Thanks a lot for reading all the way through here, and for any pointers
that can help me out.
|
|
|
| Back to top |
|
 |
Guest
|
Posted:
Fri Sep 30, 2005 12:50 pm Post subject:
Re: Trust relationship exists but still dc asks for authenti |
|
|
Thanks a lot Vince!
I'll be following your instructions in the first hours of this morning. |
|
| Back to top |
|
 |
vandresv
Guest
|
Posted:
Fri Sep 30, 2005 4:50 pm Post subject:
Re: Trust relationship exists but still dc asks for authenti |
|
|
Vince,
I rebuilt the trust but I got the same results.
Now I am in a different phase: I changed the password of the
target_domain administrator to make it the same like the source's
administrator and created a 'forest trust'.
Now I am able to add users of the other domain to any local group
without requiring to input any authentication.
But I found another obstacle, this time with ADMT:
If I tried to migrate the password, I received the error:
'Unable to establish a session with password export server. Access is
denied'.
(I have the password migration dll, installed with the target domain
generated .pes file, according with instructions. Meaning that I have
already set to 1 the allowpasswordexport key, and the
tcpipclientsupport, and reboot the source domain controller)
I have audit enable and all I got is 3 events been logged when I try to
use the password server (from the target):
1- Special privileges assigned to new logon (success0
2-Successful Network logon
3-Fifteen to Twenty seconds after previous event I got a 'suc cess
logoff event.
Thanks a lot, |
|
| Back to top |
|
 |
vandresv
Guest
|
Posted:
Fri Sep 30, 2005 4:50 pm Post subject:
Re: Trust relationship exists but still dc asks for authenti |
|
|
| funny I changed your name to Vince, sorry Vincent |
|
| Back to top |
|
 |
vandresv
Guest
|
Posted:
Sat Oct 01, 2005 12:50 pm Post subject:
Re: Trust relationship exists but still dc asks for authenti |
|
|
Solved!!!
I had selective authentication on, changed it to wide-forest
authentication and it worked!
Thanks for your help |
|
| Back to top |
|
 |
Vincent Xu [MSFT]
Guest
|
Posted:
Mon Oct 03, 2005 8:50 am Post subject:
Re: Trust relationship exists but still dc asks for authenti |
|
|
Hi,
Glad to hear that your problem was resolved.
Best regards,
Vincent Xu
Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security
--------------------
| Quote: | From: "vandresv" <vandresv@gmail.com
Newsgroups: microsoft.public.windows.server.migration
Subject: Re: Trust relationship exists but still dc asks for
authentication
Date: 1 Oct 2005 05:21:24 -0700
Organization: http://groups.google.com
Lines: 6
Message-ID: <1128169284.222735.211510@g49g2000cwa.googlegroups.com
References: <1128033036.777413.50360@g49g2000cwa.googlegroups.com
$q2Uv3WxFHA.780@TK2MSFTNGXA01.phx.gbl
1128074588.845990.128860@g14g2000cwa.googlegroups.com
1128097589.479773.40070@g47g2000cwa.googlegroups.com
1128097768.427675.56260@g47g2000cwa.googlegroups.com
NNTP-Posting-Host: 206.248.85.155
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Trace: posting.google.com 1128169288 7886 127.0.0.1 (1 Oct 2005
12:21:28 GMT)
X-Complaints-To: groups-abuse@google.com
NNTP-Posting-Date: Sat, 1 Oct 2005 12:21:28 +0000 (UTC)
In-Reply-To: <1128097768.427675.56260@g47g2000cwa.googlegroups.com
User-Agent: G2/0.2
X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.7.10) Gecko/20050716 Firefox/1.0.6,gzip(gfe),gzip(gfe)
Complaints-To: groups-abuse@google.com
Injection-Info: g49g2000cwa.googlegroups.com; posting-host=206.248.85.155;
posting-account=XEL8Yg0AAABoXOCSDX5t5EqSow57z_xz
Path:
TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfeed00.sul.t-online.de!t-onli |
ne.de!border2.nntp.dca.giganews.com!nntp.giganews.com!postnews.google.com!g4
9g2000cwa.googlegroups.com!not-for-mail
| Quote: | Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:12201
X-Tomcat-NG: microsoft.public.windows.server.migration
Solved!!!
I had selective authentication on, changed it to wide-forest
authentication and it worked!
Thanks for your help
|
|
|
| Back to top |
|
 |
|
|
|
|