rusty155 Posted January 22, 2008 Posted January 22, 2008 Hi all, I am in the process of setting up an External Trust between our Admin and Curriculum Domains. Gone pretty smoothly all in all but I want to be able to use selective authentication on the Admin domain instead of Domain-wide. However when I select it and apply, I get the following error: "The domain was in the wrong state to perform the security operation." On clicking ok, I receive: "Unable to write the organization authentication information to the trust object. The error is: The domain was in the wrong state to perform the security operation." Anyone experienced this before?
Oops_my_bad Posted January 22, 2008 Posted January 22, 2008 Are the DC's on both networks 2003? I always get this mixed up, but I think you need your DC's to be running in 2003 forest functional mode.. someone will be along shortly to confirm
rusty155 Posted January 22, 2008 Author Posted January 22, 2008 Thanks TeddyKGB, This one thing that I noticed and thought could be a cause. Both DC's are Server 2003 but are currently in Windows 2000 Mixed functional level. On the Admin network I have just one DC - 2003 but on the curriculum network I have 3 DCs - PDC is 2003 and the other two are 2000. I have up until now resisted pulling the trigger on raising the Domain Functional Level and I'm not sure what effect it will have. Further advice would be great! Thanks, Charlie.
Hedghog Posted January 22, 2008 Posted January 22, 2008 yes indeed you do need both DCs to be at 2003 functional level to get trusts to work properly. Im not sure how your curriculum AD will react if you put your 2003 server to 2003 level only. Ther are other threads on this subject on this site if I can find the reference I will post it Peter
rusty155 Posted January 22, 2008 Author Posted January 22, 2008 I cannot raise my Curriculum PDC to 2003 function level as I have 2000 DCs on the Domain. The highest it can go is 2000 native (which it is in). However, my Admin PDC is currently set to 2000 mixed - so I can certainly raise the level of that to 2003 functional level because I can't see me adding any other DCs older than Server 2003. Are there any pitfalls to be aware of when raising the functional level? I can't see there being a problem as it is the only DC on the Domain but one never knows!! Thought I better check first as it's irreversible!!
Geoff Posted January 22, 2008 Posted January 22, 2008 Raising the domain and forest functional levels to Windows Server 2003 is a nonreversible task and prohibits the addition of Windows NT 4.0–based or Windows 2000–based domain controllers to the environment. Any existing Windows NT 4.0 or Windows 2000–based domain controllers in the environment will no longer function.
Hedghog Posted January 22, 2008 Posted January 22, 2008 Hi rusty155 When I was setting up a similar trust I could not get it to work unless both DC involved in the trust were at 2003 functional level. I may be wrong but since SP1 the only way you can do this is if the above is set up. Sorry!
Julian Posted January 22, 2008 Posted January 22, 2008 You do NOT need both domains to be at the same active directory level, I have a one way trust set up between a Win 2003 active directory domain, and a Win2k active directory domain. According to my tome (Mastering Windows Server 2003 by Mark Minasi) the usual problem in setting up trusts is due to DNS not working between the two domains. Certainly my experience was that I could not get the trust to work, until I got them to see each other in DNS.
rusty155 Posted January 22, 2008 Author Posted January 22, 2008 Hi thanks for the replies - perhaps I wasn't clear enough though. I have got the trust working fine - I just can't get the selective authentication working. Get the following error when I try to enable it: "The domain was in the wrong state to perform the security operation." Anyone come across this?
Geoff Posted January 23, 2008 Posted January 23, 2008 I suspect it's either a time sync problem or a DNS error. Can you check these are working ok?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now