Assigning Security through W2k3 to W2k Trusted Domains

Assigning Security through W2k3 to W2k Trusted Domains

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Assigning Security through W2k3 to W2k Trusted Domains DevGD 03-14-2006
Posted by =?Utf-8?B?RGV2R0Q=?= on March 14, 2006, 1:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Situation:
I have created a trust between two domains in two different forests. DomainA
is a mixed Windows 2003 domain. DomainB is native Windows 2000. The trust can
be validated and seems to be working in every way. I have validated on both
ends of the trust. There is no firewall blocking the servers.

Problem:
When I try to add access for a user or security group from DomainB to a
folder on a server running w2K on DomainA, I get the following error:

"Could not display objects from this location because of the following error:
No authority could be contacted for authentication. "

I can do the same steps on a windows 2003 server and it browses the domain
and adds the security just fine.

Also, I can assign security on any server or PC on DomainB with groups or
users from DomainA. OS does not seem to matter.

Process I am using to assign security
Right-click on folder, select security tab, click location and select
DomainB. This is when I get the error.

Please help.

Thanks
DevGD




Posted by Roger Abell [MVP] on March 14, 2006, 11:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Make sure that the DNS zones for all involved domains are
available for name resolution, such as by conditional forwarders
or zone transfers between the DNS servers supporting the two
forests.

--
Roger Abell
Microsoft MVP (Windows Server : Security)

> Situation:
> I have created a trust between two domains in two different forests.
> DomainA
> is a mixed Windows 2003 domain. DomainB is native Windows 2000. The trust
> can
> be validated and seems to be working in every way. I have validated on
> both
> ends of the trust. There is no firewall blocking the servers.
>
> Problem:
> When I try to add access for a user or security group from DomainB to a
> folder on a server running w2K on DomainA, I get the following error:
>
> "Could not display objects from this location because of the following
> error:
> No authority could be contacted for authentication. "
>
> I can do the same steps on a windows 2003 server and it browses the domain
> and adds the security just fine.
>
> Also, I can assign security on any server or PC on DomainB with groups or
> users from DomainA. OS does not seem to matter.
>
> Process I am using to assign security
> Right-click on folder, select security tab, click location and select
> DomainB. This is when I get the error.
>
> Please help.
>
> Thanks
> DevGD
>
>
>



Similar ThreadsPosted
Bypass W2K3 SP2 WMF Security June 6, 2007, 4:43 pm
How to disable security warning in W2k3 SP1? July 19, 2005, 3:02 pm
Folder Security/ Permissions problem on W2K3 March 1, 2006, 11:25 pm
W2k3 SP2 breaks Security Configuration and Analysis util April 7, 2007, 3:42 am
shutting down a trusted CA and raising a new trusted CA July 14, 2005, 1:32 pm
CREATOR OWNER assigning issue August 24, 2006, 12:27 pm
How Can I Add Local and Network Drive Letters to MSIE Trusted Sites Security Zone? October 15, 2007, 12:40 am
Authentication across untrusted domains March 29, 2006, 1:16 am
Setting up 2 domains with one way trust to dmz November 14, 2006, 5:58 pm
Domain Admin can't log into child domains February 15, 2006, 7:19 pm

The site map in XML format XML site map

Contact Us | Privacy Policy