Jump to content

Recommended Posts

Posted

Hi all,

 

I am in the process of setting up an External Trust between our Admin and Curriculum Domains. Gone pretty smoothly all in all but I want to be able to use selective authentication on the Admin domain instead of Domain-wide.

 

However when I select it and apply, I get the following error:

 

"The domain was in the wrong state to perform the security operation."

 

On clicking ok, I receive:

 

"Unable to write the organization authentication information to the trust object. The error is: The domain was in the wrong state to perform the security operation."

 

Anyone experienced this before?

Posted
Are the DC's on both networks 2003? I always get this mixed up, but I think you need your DC's to be running in 2003 forest functional mode.. someone will be along shortly to confirm :)
Posted

Thanks TeddyKGB,

 

This one thing that I noticed and thought could be a cause. Both DC's are Server 2003 but are currently in Windows 2000 Mixed functional level.

 

On the Admin network I have just one DC - 2003 but on the curriculum network I have 3 DCs - PDC is 2003 and the other two are 2000.

 

I have up until now resisted pulling the trigger on raising the Domain Functional Level and I'm not sure what effect it will have. Further advice would be great!

 

Thanks,

 

Charlie.

Posted

yes indeed you do need both DCs to be at 2003 functional level to get trusts to work properly.

Im not sure how your curriculum AD will react if you put your 2003 server to 2003 level only.

Ther are other threads on this subject on this site if I can find the reference I will post it

 

Peter

Posted

I cannot raise my Curriculum PDC to 2003 function level as I have 2000 DCs on the Domain. The highest it can go is 2000 native (which it is in). However, my Admin PDC is currently set to 2000 mixed - so I can certainly raise the level of that to 2003 functional level because I can't see me adding any other DCs older than Server 2003.

 

Are there any pitfalls to be aware of when raising the functional level? I can't see there being a problem as it is the only DC on the Domain but one never knows!! Thought I better check first as it's irreversible!!

Posted
Raising the domain and forest functional levels to Windows Server 2003 is a nonreversible task and prohibits the addition of Windows NT 4.0–based or Windows 2000–based domain controllers to the environment. Any existing Windows NT 4.0 or Windows 2000–based domain controllers in the environment will no longer function.
Posted

Hi rusty155

 

When I was setting up a similar trust I could not get it to work unless both DC involved in the trust were at 2003 functional level.

I may be wrong but since SP1 the only way you can do this is if the above is set up.

Sorry!

Posted

You do NOT need both domains to be at the same active directory level, I have a one way trust set up between a Win 2003 active directory domain, and a Win2k active directory domain.

 

According to my tome (Mastering Windows Server 2003 by Mark Minasi) the usual problem in setting up trusts is due to DNS not working between the two domains. Certainly my experience was that I could not get the trust to work, until I got them to see each other in DNS.

Posted

Hi thanks for the replies - perhaps I wasn't clear enough though.

 

I have got the trust working fine - I just can't get the selective authentication working. Get the following error when I try to enable it:

 

"The domain was in the wrong state to perform the security operation."

 

Anyone come across this?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...