MSFN Forum: The trust relationship between this workstation and primary domain fai - MSFN Forum

Jump to content


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

The trust relationship between this workstation and primary domain fai between w7 clients and 2003 dc

#1 User is offline   zeezam 

  • Member
  • PipPip
  • Group: Members
  • Posts: 145
  • Joined: 28-March 08

Posted 27 January 2012 - 06:07 AM

Is there any fix for this?

My w7 clients got this message several times and I have to rejoin the domain.

We are running 2003 dc and w7 clients...


#2 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 27 January 2012 - 01:20 PM

The only time you'd get it is if the computer account password no longer matches the one in AD. If it's happening frequently, is there something specific you're doing with your DCs (or with your Win7 clients) that would cause the passwords to be out of sync?

#3 User is offline   zeezam 

  • Member
  • PipPip
  • Group: Members
  • Posts: 145
  • Joined: 28-March 08

Posted 30 January 2012 - 02:24 AM

View Postcluberti, on 27 January 2012 - 01:20 PM, said:

The only time you'd get it is if the computer account password no longer matches the one in AD. If it's happening frequently, is there something specific you're doing with your DCs (or with your Win7 clients) that would cause the passwords to be out of sync?


Ok.

Not what I know. Is there anything I can check or any policy I can set for this?

#4 User is offline   IcemanND 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,266
  • Joined: 24-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 30 January 2012 - 11:36 AM

I've been seeing the same thing in my environment and have yet to find the cause. If you have NETDOM you can use it to resync the computer account password with the domain. Or you can unjoin the machine form the domain, not need to perform the reboot, then rejoin it to the domain and reboot and with the exception of one machine I have not had any repeat customers.

#5 User is offline   TheWalrus 

  • N.W.O.
  • PipPipPipPipPip
  • Group: Members
  • Posts: 910
  • Joined: 11-August 08
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 30 January 2012 - 12:49 PM

This happens semi-regularly in out customer's domain. The trouble is there are two DCs and the secondary somehow acts as primary or something. The PC's account is created on the secondary, but nothing shows up on primary.

#6 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 30 January 2012 - 08:16 PM

Well, password synchronizations are done on the PDC emulator first, and then replicated out. If you look at the event logs for both, I'm guessing one (or both) of them are having issues. There should be event viewer interesting'ness on the DCs, at least, and maybe the clients too.

#7 User is offline   IcemanND 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,266
  • Joined: 24-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 30 January 2012 - 08:24 PM

Cluberti, you know anything specific we could look for? I've glanced at the client logs but never noticed anything useful. I don't have access to the DCs to look at those logs but if I had any starting point I would be better off than I am now.

#8 User is offline   Cyrius 

  • Newbie
  • Group: Members
  • Posts: 41
  • Joined: 10-October 11
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 23 February 2012 - 10:00 AM

I have gotten this a few times and resetting it to the old password through AD Users and Computers allowed me to get back in.

This typically has happened on my Road Warrior laptops which are not often connected to my actual domain, but which are a member.

This post has been edited by Cyrius: 23 February 2012 - 10:10 AM


#9 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 23 February 2012 - 05:47 PM

@IcemanND, you would need to look at the logs on the DCs.

#10 User is offline   IcemanND 

  • MSFN Junkie
  • Group: Super Moderator
  • Posts: 3,266
  • Joined: 24-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 23 February 2012 - 07:22 PM

I was afraid of that. And with as random as it happens finding something useful in them can be next to impossible with six DC's to dig through.

#11 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 23 February 2012 - 08:57 PM

Password changes happen first on the pdc - use ntdsutil to figure out which one that is, and that's the one to look at for starters. If it was easy, we could replace you with the janitor! :)

#12 User is offline   tj18 

  • Group: Members
  • Posts: 2
  • Joined: 26-February 12
  • OS:Server 2008 x64
  • Country: Country Flag

Posted 26 February 2012 - 11:21 AM

Thanks - The replies here helped shed some light on my issue - but still need more assistance. Will make a separate post.. and will probably need to learn the syntax's of ntdsutil.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy