Urgent: cannot join to newly setup server/domain

  • Thread starter Thread starter Hartmut Berghoff
  • Start date Start date
H

Hartmut Berghoff

Hello all,

I hva to recover a server after only a fresh install was possible.
Now I managed all, but no workstation will join the domain.

- I install the server
( by reason of some problems with the first networkcard I confiured both,
the old installation had only the broadcom gigabit, now there is the
intel 10/100 as 2nd )
- I setup dns with my old dns-files (included the service entries of the old
installation
- I created an new active directry
(same domainname and netbios domainname as the old server)
- I enterde the computers, users and groups to the ADS-database
- I removed a workstation from the old domain and joined the workgroup X
(change name-function in the system-applet)
- I did the same back to the domain
- Login to the domain failed (some hints in the eventlogs: )pardon, I
translate this messgae from german)
" The computer PC-NAme tried to connect to server 'name of
domaincontroller', using a trusted relationship. Thsi PC has lost the
correct SID, whe the domain was newly configured. Establish a new
trust-relationship"

2nd:
Establish Session refused by reason of authentication. Accountname in the
security database ist 'PC-Name'. Error is: Access denied.

I suppose, somethingbeing wrong with the srv entries of dns.
What do you mean.
Please help, so that I can avoid to deinstall and reinstal ADS
/The network should be back uo and running at monday morning latest.

Thanks
hartmut
 
Hello all,

I had to get some sleep. Now, being awake, I sadly recognize, there is no
gelping answer for my problem. So I will take my breakfast and take the
unwnated step to remove ADS and set it up once more.

Hartmut
 
Hi Helmut-

It sounds like you had a problem with your sole DC and no backups were
available, so you created a new DC/domain of the same FQDN and NetBIOS name.
If that is the case, the reason your clients are getting access denied
errors is that the new domain, though it is ostensibly named the same, is
different.

There are unique identifiers for domains and DCs, such as the domain GUID,
the forest GUID et cetera. Each domain and each DC have unique ones no
matter what.

To work around this, disjoin your client machines and join them to the new
domain of the same name.
 
Back
Top