Windows Server 2003
1836867 Members
2249 Online
110110 Solutions
New Discussion

the trust relationship cannot be created

 
Alberto Mendoza
Advisor

the trust relationship cannot be created

Hi.

I need to establish the trust relationship between two domains Win NT and Win 2003 Srv.

I have the following error in the DC Win 2003: The local security authority is unable to obtain an rpc connection to the domain controller WinNT


This trust relationship alredy was established but it is had lost.

Thanks
Thanks
3 REPLIES 3
Ivan Ferreira
Honored Contributor

Re: the trust relationship cannot be created

You must create an external trust relationship, remember that is one way non transitive.

Before you can create
an external trust, you must configure a DNS forwarder on both of the DNS servers
that are authoritative for the trusting domains.

To configure a DNS conditional forwarder, complete the following steps on both
authoritative DNS servers:

Click Start, point to Administrative Tools, and then click DNS.

In the console tree, right-click the DNS server you want to configure, and then
click Properties.

In the Properties dialog box for the DNS server, click the Forwarders tab.

On the Forwarders tab, specify the DNS domain names that require queries to
be forwarded (conditional forwarding) in the DNS Domain box by clicking New
and typing the domain name in the New Forwarder dialog box. Type the IP address or addresses of the server or servers to which
the queries are forwarded in the Selected Domainâ s Forwarder IP Address List,
and then click Add.
Por que hacerlo dificil si es posible hacerlo facil? - Why do it the hard way, when you can do it the easy way?
Alberto Mendoza
Advisor

Re: the trust relationship cannot be created

I have in the forwardes the ip of the server to establish the trust relationship. However, not yet i can make the trust between both domain, i have the same one error.

In the domain NT, i need modify the parameters??

Thanks
Ivan Ferreira
Honored Contributor

Re: the trust relationship cannot be created

Yes, on the NT domain you need a Authoritative DNS server for the domain, and a forwared configure too. (That whats the theory says)
Por que hacerlo dificil si es posible hacerlo facil? - Why do it the hard way, when you can do it the easy way?