Discussion:
Breaking and Re-Establishing a Forest Trust Relationship
(too old to reply)
Darren King
2008-05-14 10:05:40 UTC
Permalink
Dear All,

We are having issues with an existing Forest Trust Relationship which we are
having problems addressing:

- Time Synchronisation, which has now been corrected
- One Forest was 2003 Native and the other was Windows 2000 (mixed mode)
when the Trust was established, which I think could have caused issues.
- Persistently failing DCDIAG's on Outbound Secure Channels (DC Domain A
Does not have downlevel trust object for DC Domain B - this occurs for all
DCs in both directions)

I am considering the option of breaking the Trust and starting from scratch
with a clean slate. Can anyone clarify how this would affect cross-Trust
permissions? Would they all be lost? Or once the Trust was reestablished
would they then work again?

Any advice is greatly appreciated.

Regards,

Darren
Paul Bergson [MVP-DS]
2008-05-14 12:54:48 UTC
Permalink
Once you break the trust relationship, it has to be re-established but any
acl's previously defined should work once the trust is re-established.

---Trust Diagnostics---
Test the trust relationship between two domains

netdom trust trusting_domain_name /Domain:trusted_domain_name /verify

If you would like to test connectivity to validate FRS communication
NTFRSUTL version server_name
If the two can communicate through the firewall via
FRS the response will provide the current version number


If you would like to validate connectivity between the domains use the tool
PortQryUI
Download PortQryUI and run the tool
Select the destination DC
Select Domains and Trusts
Validate the ports that should be open in fact are
via the output provided by the tool.
For additional info on this tool see
PortQry features, this is the backend tool for PortQryUI

PortQry
http://support.microsoft.com/default.aspx/kb/832919/


---Trust Creation---
To start would have to establish dns connectivity both ways, usually the
easiest thing to do would be to create secondary's of each others primary.

http://expertanswercenter.techtarget.com/eac/knowledgebaseAnswer/0,295199,sid63_gci1104911,00.html

Once established you can then go and create your Forest trust, this
establishes a two trust.

Creating an Forest Trust
http://technet2.microsoft.com/windowsserver/en/library/7929b0c4-efe1-409c-99e3-efe9815f426d1033.mspx?mfr=true
--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.
Post by Darren King
Dear All,
We are having issues with an existing Forest Trust Relationship which we
- Time Synchronisation, which has now been corrected
- One Forest was 2003 Native and the other was Windows 2000 (mixed
mode) when the Trust was established, which I think could have caused
issues.
- Persistently failing DCDIAG's on Outbound Secure Channels (DC Domain
A Does not have downlevel trust object for DC Domain B - this occurs for
all DCs in both directions)
I am considering the option of breaking the Trust and starting from
scratch with a clean slate. Can anyone clarify how this would affect
cross-Trust permissions? Would they all be lost? Or once the Trust was
reestablished would they then work again?
Any advice is greatly appreciated.
Regards,
Darren
Continue reading on narkive:
Loading...