SC lost trust relationship between parent-child domains

Discussion in 'Active Directory' started by Oswaldo., Mar 24, 2005.

    I have some troubles with Windows AD2k trust relationships between
    parent-child domains.
    when I try to verify ( and then reset sc ) the trust relationship by using
    domains and trusts it shows me the error:

    The database on the server does not have a computer account for this
    workstation trust relationship

    Whenever I try to use nltest to reset the parent domain SC on the child DC i
    got the error:

    I_NetLogonControl failed: Status = 5 0x5 ERROR_ACCESS_DENIED

    I_NetLogonControl failed: Status = 5 0x5 ERROR_ACCESS_DENIED

    Im using an enterprise admin account to log on to the servers.

    Any help would be greatly appreciated

    Oswaldo., Mar 24, 2005
    ptwilliams Guest

    This is a DNS problem. The trust is maintained by the PDCe in each domain.
    Therefore the DCs need to be able to resolve DCs and PDCe SRV records in
    both domains.

    How is your name resolution setup?

    Usually a delegation is made in the parent to the child, and the child holds
    a secondary of the parent or forwards to the parent.


    Paul Williams
    ptwilliams, Mar 24, 2005
    that is the way DNS resolution is working.

    Parent domain has a delegation to the child domain and both domains hold a
    secondary zone for its opposite. already checked NSLOOKUP from child to
    parent domain servers and viceversa and worked fine.

    any suggestion?

    Oswaldo., Mar 25, 2005
    ptwilliams Guest

    Have you tested SRV records though? Standard name-to-IP is good, but not
    everything. You should also check that you can resolve the and records.

    Otherwise, there's a host of KB articles in this link that might be of help:

    Please let us know if any of this helped.


    Paul Williams
    ptwilliams, Mar 30, 2005
