Re: Cluster File Share cannot be accessed by account on trusted domain

From: Mike Rosado [MSFT] (mikeros_at_online.microsoft.com)
Date: 09/09/04


Date: Thu, 9 Sep 2004 14:57:29 -0500

Jeff,

You meantion in the original posting:

"Although I have explicitly added domain accounts from a trusted domain in
the same forest as the cluster servers, I am not able to access the share
using these account credentials."

Have you tried the following by editing the registry? See reference
article below which may shed some light with regards to complications of
LMCompatibilityLevel across trusted domains.

1. Start Registry Editor (Regedt32.exe).

2. Locate and click the following registry key:

  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa

3. Double-click LMCompatibilityLevel. (does not have to be case sensitive)

4. Change the Radix setting to Decimal, and then type the number "0" in
   the Data box. Click OK.

5. Quit Registry Editor.

6. Restart the server.

823659 Client, service, and program incompatibilities that may occur when
you
http://support.microsoft.com/?id=823659

-- 
Hope this helps,
Mike Rosado
Windows 2000 MCSE + MCDBA
Microsoft Enterprise Platform Support
Windows NT/2000/2003 Cluster Technologies
====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
<http://www.microsoft.com/info/cpyright.htm>
Delighting customers is our top priority. We welcome your valuable comments
and suggestions about how to improve the service we provide you. So if you
would like provided us feedback, feel free to e-mail my manager Brian
Pennington then click on the following e-mail hyperlink with a short
statement with regards to your Online support experience
<mailto:BPenning@microsoft.com?subject=Newsgroup_Experience&body=Brian,>.
Thank you.
-----Original Message-----
<anonymous@discussions.microsoft.com> wrote in message
news:903201c49692$c77fa740$a501280a@phx.gbl...
> The two cluster nodes are domain controllers.  They do
> not have group policy enabled on them directly.  I
> believe there is a default domain policy but nothing was
> configured (outside the defaults) in this policy.  Is
> there something I should be looking for in there that
> would affect the file shares in this manner?
>
> I don't have any problems contacting the same share
> directly off the cluster node hosting the virtual server
> using the non-local domain accounts credentials.
>
> The NTFS permissions are correctly set and the non-local
> domain account is explicitly specified.  In fact, I have
> installed the hotfix in KB Article 834231 on both cluster
> nodes.
>
> >-----Original Message-----
> >Hi Jeff,
> >
> >Have you tried to create a NEW OU (Organizational Unit),
> copy the two
> >cluster nodes into the new OU and select "Block Policy
> Inheritance" on the
> >Group Policy tab of the properties on the new OU?
> >
> >Have you checked the NTFS permissions on the actual File
> Share?
> >
> >-- 
> >Hope this helps,
> >Mike Rosado
> >Windows 2000 MCSE + MCDBA
> >Microsoft Enterprise Platform Support
> >Windows NT/2000/2003 Cluster Technologies
> >
> >====================================================
> >When responding to posts, please "Reply to Group" via
> your newsreader so
> >that others may learn and benefit from your issue.
> >====================================================
> >
> >This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ><http://www.microsoft.com/info/cpyright.htm>
> >
> >Delighting customers is our top priority. We welcome
> your valuable comments
> >and suggestions about how to improve the service we
> provide you. So if you
> >would like provided us feedback, feel free to e-mail my
> manager Brian
> >Pennington then click on the following e-mail hyperlink
> with a short
> >statement with regards to your Online support experience
> ><mailto:BPenning@microsoft.com?
> subject=Newsgroup_Experience&body=Brian,>.
> >Thank you.
> >
> >-----Original Message-----
> >
> >"Jeff" <anonymous@discussions.microsoft.com> wrote in
> message
> >news:86b401c495e8$9e20af70$a301280a@phx.gbl...
> >> I have a file share on a Windows 2003 Enterprise
> Edition
> >> server cluster.  I am able to access the file share
> over
> >> the network using local domain accounts without any
> >> problems.  Although I have explicitly added domain
> >> accounts from a trusted domain in the same forest as
> the
> >> cluster servers, I am not able to access the share
> using
> >> these account credentials.  I keep getting prompted
> with
> >> the password dialog box even though I know I am
> entering
> >> the correct password.  Any suggestions?
> >
> >
> >.
> >


Relevant Pages

  • Re: Point and Print Restrictions policy
    ... You will need to enable DNS registration in order for the cluster name to ... Client side ... Disable the policy in a domain GPO that applies to all users (the policy is ... enabled since it's not configured by default) or add the server names to the ...
    (microsoft.public.win2000.printing)
  • Re: Cluster Build problem - Cluster Service wont start and install
    ... The server is currently in an OU that specifically does not get any Group ... Policy with the exception of a Domain Policy, and that GP only sets high ... setup fails when the Cluster Wizard attempts to start the Cluster Service. ...
    (microsoft.public.windows.server.clustering)
  • Cluster failure
    ... Hi i have installed a cluster server on windows 2003 server enterprise ... Everhting works fine until we apply our baseline policy for the server. ... After the policy have applied we cant start the cluster service.. ... we suspect it has something to do with our account restrictions as logon as ...
    (microsoft.public.access.security)
  • Re: NLB Cluster - Ping fails or long time to reply from outside local subnet - SOLVED
    ... Windows Server 2008 Readiness Team ... cluster on a separate DLink card in multicast mode. ... I thought that the litmus test was that the router functions fine ... member of the NLB cluster, setup NLB on it, plug the NICs ...
    (microsoft.public.windows.server.clustering)
  • Re: NLB Cluster - Ping fails or long time to reply from outside local subnet - SOLVED
    ... Once again, ARP is an RFC standard, if you are having to make static entries in unicast mode, then your network device is not in compliance. ... Windows Server 2008 Readiness Team ... I was feeling nervous about our teaming-capable adapter as I read it might be sending out heartbeats, so I disabled it AND configured the cluster on a separate DLink card in multicast mode. ... I thought that the litmus test was that the router functions fine when no NLB is installed, but when it is, things start going screwy. ...
    (microsoft.public.windows.server.clustering)

Loading