One Way Forest trust broken


we have 1 way forest trust partially broken. can log in server on trusting domain trusted domain account. domain admin in trusting domain, when try list members of local group trusted domain users added, show sids , top error in screenshot. when try add trusted user group, second error after authenticating trusted domain , selecting name list of available users. third error in system log on trusting domain controller i'm trying add user trusted domain.

when googling each error message, i've followed suggested resolution no avail. there no firewall between trusted , trusting domain controllers in question. (they on same ip subnet) ipv6 enabled.

i've enabled security-kerberos log , tried add user group described above. i've pasted error below:

service principal name (spn) krbtgt/trusted.domain.com@trusting.domain.com not registered, caused kerberos authentication fail: 0x7. use setspn command-line tool register spn.

thanks in advance.


the answer issue ended being change gpo domain controllers in trusting domain.

by disabling setting , rebooting trusting domain controllers, works again should.

computer configuration -> administrative templates -> system -> remote procedure call "rpc endpoint mapper client authentication"

this supporting documentation:

https://support.microsoft.com/en-us/kb/3073942



Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group