Windows Server 2000/2003 Thread, Trusting domains for a federation in Technical; Hi,
My school was recently federated, and as such I have been asked to give the teachers the ability to ...
30th June 2009, 01:45 PM #1
- Rep Power
Trusting domains for a federation
My school was recently federated, and as such I have been asked to give the teachers the ability to log on to both schools with the same username and password and with the same Home area and shared drives.
We are a kent school and both schools are using the same Internet service provided by EIS. As such, the easiest and least expensive way to link the schools was to open up the ports between both schools. I am now able to remotely log on to their servers and vice versa.
This is where things get shakey. I thought the best way to give the teachers what they need was to set up domain trusts (which I have never done before) and then give them the option of which domain to login to on the logon page. I believe I have set up the domain trusts OK. In My schools DNS I can see the federated school and vice versa. When you get to a logon screen here you have the option of which domain to log on to. SO I choose the other schools domain and used a username and password from their domain, but when I do this I get the error message "The system cannot log you on now because the domain <DOMAIN NAME> is not available".
COuld anyone point me in the right direction with this? I'm convinced that I'm either going about this whole thing the wrong way, or I've made some small error in the setup.
IDG Tech News
1st July 2009, 08:17 AM #2
- Rep Power
There needs to be a two way trust between the domains (I seem to recall that Microsoft call it something else now, but that's effectively what it is)
Are the clients timing out over the internet link? May have to tweak group policy - wait for network to be available etc. Do you need to 'apportion' a section of the internet link between the two schools with QOS via a router maybe? You don't want connections dropping coz some teacher thinks that video streaming for 30 kids is a great idea.
1st July 2009, 11:48 AM #3
- Rep Power
Hi, thanks for the suggestions.
A 2 way trust has been set up, sorry for not being clear on this. I have tried logging on during "off-peak" hours with little to no network or internet traffic but this does not help.
I realsied last night that I had not pointed the workstation to the other schools DNS. Once i did this, rebooted the machine and tried again, I got a new message
"Unable to log you on because of account restrictions".
The account has full admin rights on the other schools network.
1st July 2009, 11:54 AM #4
Just a quick note, when you modify DNS, make sure the local DNS is still primary, then any external DNS for internet or another domain are secondary.
As for the error message "Unable to log you on because of account restrictions", this could be for a whole range of reasons. The security settings, such as password requirements may differ from one site to the other. Another example are time restrictions which can also prevent you from logging on.
1st July 2009, 12:36 PM #5
- Rep Power
The plot thickens.
I remoted in to the other schools forest root server. I wanted to check the trusts again so I went in to Active Directory Domains and Trusts. I right clicked on the root of it and clicked connect to domain controller. Typed in my own schools domain name and got
"The configuration information describing this enterprise is not available. No authority could be contacted for authentication."
Yet when I log on to my own schools forest root and attempt to connect to the other school's DC in the same way, it works perfectly.
By elsiegee40 in forum Educational IT Jobs
Last Post: 27th March 2009, 09:02 AM
By Harris in forum Educational IT Jobs
Last Post: 18th October 2007, 04:07 PM
By Darms in forum Educational IT Jobs
Last Post: 29th June 2007, 10:29 AM
By localzuk in forum General Chat
Last Post: 22nd May 2007, 08:35 AM
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Tags for this Thread