4.65 TrustRelationship

Use this Knowledge Script to test the domain trust relationship from the computer where you run this script to a specified domain. The domain of the managed computer running this script is considered the trusting or resource domain. The domains you specify as script properties are the domains you expect to be trusted domains. This script raises an event if there are problems with the domain trust, such as when a trusted password is no longer valid or the Primary Domain Controller of the trusting domain cannot be located.

NOTE:Before running this script, be sure the netiqmc and netiqccm services are set to run as a domain user account with Administrator privileges in both the trusting and trusted domains. For example, to test whether Domain A still trusts Domain B, the agent services must run as an account with domain Administrator privileges in both Domain A and Domain B. Use the Services Control Panel to identify an account for the service to run as.

4.65.1 Resource Objects

Windows 2003 Server or later

4.65.2 Default Schedule

The default schedule for this script is Every 30 minutes.

4.65.3 Setting Parameter Values

Set the following parameters as needed:

Description

How to Set It

Raise event?

Set to y to raise an event if there are problems with the domain trust relationships. The default is y.

Collect data?

Specify whether to collect data for charts and reports. If enabled, data collection returns:

  • 100 -- the domain of the managed computer trusts the domains entered, or

  • 0 -- the trust relationship is broken.

The default is n.

Trusted domains

Provide a list of trusted domains, separated by commas with no spaces. Trusted domains contain resources that computers in other domains can use.

Event severity level

Set the event severity level, from 1 to 40, to indicate the importance of an event in which there are problems with the domain trust relationships. The default is 35 (red event indicator).