Home > Windows Server Tips > Active Directory Administration > Troubleshooting a cross-forest trust in Active Directory
Windows Server Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

ACTIVE DIRECTORY ADMINISTRATION

Troubleshooting a cross-forest trust in Active Directory


Gary Olsen, Contributor
03.25.2008
Rating: -4.50- (out of 5)


Expert advice on Active Directory and Group Policy
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Errors are likely to occur either when creating, validating or using a cross-forest trust. Typical errors you'll see are "unable to contact the domain" or "domain is not available."

The first thing to check is DNS. Let's go back to a scenario created in a previous article on how to create a cross-forest trust in Active Directory:

Let's consider two forests, Corp.net and ABC.com. There is a child domain, NA.corp.net, in the Corp.net forest, but ABC.com is a single domain forest. Our goal will be to create a two-way trust between the Corp.net domain and the ABC.com domain. Because it's a transitive trust, the NA domain will be able to use the trust as well.

In that scenario, secondary zones or conditional forwarders that point to the other domain/forest should have been created. For example, define a secondary zone for ABC.com in the Corp.com DNS servers and vise versa.

To test DNS, try the following:

Next, verify the trust by going to the Domains and trusts snap-in. Right-click on the domain icon, and in the trusts tab, select the trust and click Properties. In the Properties tab, click the Verify tab. If the trust is created but can't be validated, delete both sides of the trust and recreate. The error can often be corrected in this manner.

If the trust is created and validated but you can't do trusted operations, such as l


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Microsoft Active Directory Tools and Troubleshooting
Troubleshooting poor Windows logon performance in Active Directory environments
New Operations Manager 2007 feature allows for automated agent deployments
Taming the LSASS.exe process for Active Directory performance and security
Active Directory FAQs
Troubleshooting Active Directory database errors
Bad external time source stops Active Directory replication
Time stamps change with daylight-saving time
DNS troubleshooting tips for Active Directory
How the DC locator works in Active Directory
Unwinding USN rollback when faced with AD replication failure

Active Directory Administration
Using Active Directory to manage Macs in a Windows environment
Troubleshooting poor Windows logon performance in Active Directory environments
Common Active Directory security oversights
Scripting domain controller installations: A must for Server Core
Taming the LSASS.exe process for Active Directory performance and security
Troubleshooting Active Directory database errors
Active Directory database basics: Performing an offline defrag
Branch office security: Pros and cons of read-only domain controllers
Tips for Windows domain controller optimization
How to rebuild the SYSVOL tree when none exists in Active Directory

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ogging in across the trust or finding users in the other forest, check the system time in both forests. The system time on the PDC in the root domain in both forests must be synchronized. You can do this manually or configure them to point to an external time source.

Perform the following operations to verify functionality of the trust:

It is important to note that when you create a trust, you determine the level of security you want. That is, you can have it wide open so that authenticated users in one forest have the same rights as authenticated users in the other, or you can set it so that you must explicitly grant access to resources in the other domain. This can be changed after the trust is built via the trust wizard.

And make sure the time is synchronized in the domains. Even if a trust is successful, if the time gets out of sync, the trust will fail. The best way to do this is to set the root domain PDC of each forest to point to the same external time source. Remember, however, that Kerberos tickets are not encrypted going across a cross forest trust.

Gary Olsen is a systems software engineer for Hewlett-Packard in Global Solutions Engineering. He wrote Windows 2000: Active Directory Design and Deployment and co-authored Windows Server 2003 on HP ProLiant Servers. Olsen is a Microsoft MVP for Windows Server-File Systems.


Rate this Tip
To rate tips, you must be a member of SearchWindowsServer.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Server Room Design - Planning, Cooling, Maintenance
HomeTopicsBlogsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts