Computing.Net > Forums > Windows Server 2003 > Creating Trust between NT4 and 2003

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Creating Trust between NT4 and 2003

Reply to Message Icon

Name: Nibbs
Date: January 19, 2006 at 02:04:36 Pacific
OS: NT4.0 and Win2003
CPU/Ram: 2x 3.2GHz Xeon 2Gb RAM
Comment:

I have a problem with creating a trust between NT4 and Windows 2003 Server. The message I get is:

"Could not find domain controller for this domain"

I am starting the process of a migration of a NT4 domain to a Windows 2003 domain. I am trying to setup a trust between one of the 2003 DCs (there are two) and the NT4 PDC in the other domain. I have added the servers on both ends into lmhosts files and even configured WINS on both domains and am able to ping the servers by IP and NetBios names.

I am trying to setup a two-way trust so configured the trust on the 2003 DC first (following KB Article 325874).

Everytime I try to setup the "Trusted Domain" on the NT4 box I get the "Could not find domain controller for this domain".

Aswell as following the steps in the KB Article 325874, http://support.microsoft.com/default.aspx?scid=kb;en-us;325874, I have also followed the "troubleshooting" steps in that article at the bottom for this exact problem. It lists 3 solutions and I have confirmed all 3 of them.


There is one thing, when following the instructions in the KB article for setting up the trust on the 2003 DC, What I see is different to what is explained in the article...

The article says:

d. The New Trust Wizard appears. Click Next to continue.
e. Type the NetBIOS name of the Windows NT domain for this trust. For example, type supplier01-int, and then click Next.
f. In the Direction of Trust window, click One-way: outgoing
Users in the specified domain, realm, or forest can be authenticated in this domain.
g. Click Next, and then click one of the following to select the scope of authentication for users from the Windows NT domain: • Allow authentication for all resources in the local domain
Windows authenticates users from the specified domain for all resources in the local domain. This option is preferred when both domains belong to the same organization.
• Allow authentication only for selected resources in the local domain
Windows does not automatically authenticate users from the specified domain for any resources in the local domain. After you finish this wizard, grant individual access to each server that you want to make available to users in the specified domain. This option is preferred if the domains belong to different organizations.

h. Click Next, and then type a password for this trust in the Trust password box. You must use the same password when you create this trust relationship in the specified domain. After you create the trust, Active Directory periodically updates the trust password for security purposes. Type the password again in the Confirm trust password box, and then click Next.
i. Review your settings, and then click Next.

What I get is the following:

- I type the name of the domain and click Next
- The name you specified is not a valid windows domain Is the sepcified name a V5 Kerboros Realm, choose either 'Realm Trust' or 'Trust with a windows domain' Specified domain: <domainname>
- If i choose option 2 and put in the domainname then another windows apppears with the message "Cannot continue, the new trust wizard cannot continue because the specified domain connot be contacted". Finish or cancel.
- If I choose the other option it asks for questions about setting up transitive/non-transitive trusts aswell as two-way or one-way and then asks for the password. It sets up the trust but I still get the same problem when I try and set the trust from the NT PDC "Could not find domain controller for this domain".

Any help would be MUCH appreciated. Thanks.




Sponsored Link
Ads by Google

Response Number 1
Name: Nibbs
Date: January 19, 2006 at 08:16:06 Pacific
Reply:

FOr anyone interested I have resolved this myself now.

Even though I had created an LMHOSTS file, the format was not 100% correct, I followed this article:

http://support.microsoft.com/d...?scid=kb;en-us;Q180094

From my 2003 DC I was then able to create the two-way trust that I wanted.... magic!! :-)


0
Reply to Message Icon

Related Posts

See More


Windows 2003 and folder p... Won't recognize hard driv...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Server 2003 Forum Home


Sponsored links

Ads by Google


Results for: Creating Trust between NT4 and 2003

Migrate Accounts from NT4 to Win2k3 www.computing.net/answers/windows-2003/migrate-accounts-from-nt4-to-win2k3/2740.html

NT 4 to 2003 Migration www.computing.net/answers/windows-2003/nt-4-to-2003-migration/2010.html

Trust between DMZ & production www.computing.net/answers/windows-2003/trust-between-dmz-production/9460.html