RODC Issue
Hi, I am testing rodc in test envorenment having one 2008r2 dc, one 2008r2 rodc and one windows 7 client on same network. I added one user to password pre-populate list. Then after giving some time to replicate settings, I disconnected dc and tried to login win7 client. also I applied group policy setting to not cache password locally on win7 client. It says trust failed between workstation and primary domain. Is there any wrong configuration and if not how rodc can be tested???
January 23rd, 2011 2:37am

Hi, Thanks for the post. Please understand that the credentials of cacheable accounts aren’t actually cached until after the initial logon to an RODC when the authentication request is forwarded to a Windows Server 2008 R2 writable DC and the credentials are replicated to the RODC. This means that if network connectivity to a writable DC becomes unavailable before cacheable accounts are authenticated against an RODC, successful logon will fail even though the accounts have been configured as cacheable. Here is some useful information you could refer to: http://technet.microsoft.com/en-us/library/cc753470(WS.10).aspx http://technet.microsoft.com/en-us/magazine/ff679947.aspx Hope this helps. MilesPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
January 24th, 2011 3:25am

Hi, Thanks for your attention! I verified the cached credential by "repadmin /prp view RODC_name reveal " and it shows the user. Also when I opened ADUC at rodc it shows the user when rwdc is disconnected. So I understand I gave enough time to replicate. And what does "prepopulate" option mean when I cannot cache immedeatly passwords?? And if still it is replication issue, please suggest me way (if possible then something like step-by-step docs) to simulate rodc before I can actully deploy it in production. One thing I would like to remind I have applied group policy " Do not cache password locally on win7 client". Is there any help?
January 24th, 2011 5:20am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics