question

joelwx-5141 avatar image
0 Votes"
joelwx-5141 asked joelwx-5141 commented

netdom for windows 7 embedded

A full disk backup image of win7 embedded was created by ghost after the machine joined AD 5 month ago
last week,the hard drive is broken,we restore the machine after replace the HD.
booting up is ok,but we can not login with the ad account.
error msg: lost trust relationship with domain controller.
after same research ,we believe its a machine password issue.
netdom is the right tool for reseting the machine password,but we can not find such command for win7 embedded.
where can i get this?

windows-active-directorywindows-embedded-standard7
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
1 Vote"
LimitlessTechnology-2700 answered Sean-Liming commented

Hello

Windows Embedded has a write lock/filter that might prevent this changes, check about it and how to diable here: https://docs.microsoft.com/en-us/previous-versions/windows/embedded/ff769914(v=winembedded.60)?redirectedfrom=MSDN

In the case of this version, I would strongly recommend to commit a manual rejoin to the domain

Best regards!

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LT-2700 has a good idea. Please check to see if EWF (ewfmgr.exe) or FBWF (fbwfmgr.exe) are in the image. Disable them, and reconnect to the domain. Every 30 days a new domain secret key is generated since the current key is not in the back up image, you will have to re-establish links to the AD.

0 Votes 0 ·
joelwx-5141 avatar image
0 Votes"
joelwx-5141 answered joelwx-5141 commented

thanks guys for replying
a manual rejoin is rejected by manager.
so, that leave me no choice.
I'm a little confused.
will win7 em rebuild the trust relationship automaticly if EWF/FBWF is disable?
or I still need something like netdom to repair the true relationship?
thanks again.

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

What is the managers reasoning? The problem is that the trust relationship has to be re-established since the private key is old.

Which filter is enabled in the image? FMWF or EWF?

netdom runs from the server side.

If you have a Microsoft sales contact that you work with. I suggest that you contact them to see if there is an alternative to fixing the AD trust relationship.

0 Votes 0 ·
joelwx-5141 avatar image joelwx-5141 Sean-Liming ·

sorry for the delay.
the reason of no manual rejoing are:
1. manual rejoing=5 m
2. application setting modification = 30 m (manual only; GPO/relacing config file did not work)
total time cost is about 35 m ,that is the reason.....
I am still waiting for the answer from vendor about FMWF /EWF.
thanks


0 Votes 0 ·
cthivierge avatar image
0 Votes"
cthivierge answered joelwx-5141 commented

If you are admin of the Windows 7, you could try to reset the computer password using the nltest command:

Open a Command prompt using Admin rights

nltest /sc_reset:Domain\DC_Name

ex: for a domain called lab.net and a DC called DC01, the command will be:

nltest /sc_reset:lab\DC01

hth

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

I will do a test for NLTEST.
come back later.
thanks

0 Votes 0 ·