K
Karsten
A couple of days ago one of our Windows 2000 servers (domain member)
started getting access denied when trying to log on to the domain. The
error message on this server is "The system cannot log you into this
domain because the system's computer account in it's primary domain is
missing or the password on that account is incorrect." Also in the Event
log I repeatedly see event ID 3210 "Failed to authenticate with
\\<computer name>, a Windows NT domain controller for domain <domain
name>." Local Administrator log on still works.
Also, when trying to join the domain I receive Event ID 5722 on the DC.
On the DC, when trying to join the W2K server using NETDOM I receive the
message "The trust relationship between this workstation and the primary
domain failed."
The domain is running in mixed mode with one NT4 DC, one Win2K DC and
one Win2003 DC, which is also the global catalog server.
These are the suggested solutions that I found in newsgroups and the
results:
- Use NLTEST to test the trust relationship. Result: 'Trust relationship
failed'
- Use NETDOM to join the affected computer to the domain after manually
removing it. Result: 'Trust relationship failed'
- Use NETDOM to reset the secure channel. Result: 'Trust relationship
failed'
- Log on to the domain with a different domain user name with admin
rights. Result: 'Cannot log you on to the domain'
- Remove the affected machine from the domain, delete its computer
account in AD, wait for replication and rejoin the domain. Result:
'Cannot log you on to the domain'
One more observation: After removing the server from the domain, adding
it to a workgroup and rebooting it still claims domain membership in the
Network Identification tab of the computer's properties.
Thank you for any thoughts
Karsten
NB: I have posted this in the win2000.networking-group before I
discovered this group. Sorry for crossposting.
started getting access denied when trying to log on to the domain. The
error message on this server is "The system cannot log you into this
domain because the system's computer account in it's primary domain is
missing or the password on that account is incorrect." Also in the Event
log I repeatedly see event ID 3210 "Failed to authenticate with
\\<computer name>, a Windows NT domain controller for domain <domain
name>." Local Administrator log on still works.
Also, when trying to join the domain I receive Event ID 5722 on the DC.
On the DC, when trying to join the W2K server using NETDOM I receive the
message "The trust relationship between this workstation and the primary
domain failed."
The domain is running in mixed mode with one NT4 DC, one Win2K DC and
one Win2003 DC, which is also the global catalog server.
These are the suggested solutions that I found in newsgroups and the
results:
- Use NLTEST to test the trust relationship. Result: 'Trust relationship
failed'
- Use NETDOM to join the affected computer to the domain after manually
removing it. Result: 'Trust relationship failed'
- Use NETDOM to reset the secure channel. Result: 'Trust relationship
failed'
- Log on to the domain with a different domain user name with admin
rights. Result: 'Cannot log you on to the domain'
- Remove the affected machine from the domain, delete its computer
account in AD, wait for replication and rejoin the domain. Result:
'Cannot log you on to the domain'
One more observation: After removing the server from the domain, adding
it to a workgroup and rebooting it still claims domain membership in the
Network Identification tab of the computer's properties.
Thank you for any thoughts
Karsten
NB: I have posted this in the win2000.networking-group before I
discovered this group. Sorry for crossposting.