Article ID: 119018, created on Dec 4, 2013, last review on May 20, 2014

  • Applies to:
  • Virtuozzo
  • Virtuozzo containers for Windows
  • Virtuozzo hypervisor


  • After a restore of a VM/CT backup with Domain Controller or a c2c/c2v/p2v migration of a Domain Controller, it is not possible to logon to workstations of the domain.
  • The error appears: The trust relationship between this workstation and the primary domain failed


This problem can be caused by inconsistency in Kerberos keytab, when it misses all of the automatic password changes that are executed against the domain controller. The password changes are required to maintain the security integrity of the domain.


There can be several ways to fix the issue:

  1. Reset the computer account and re-join the workstation to the domain.

    1.1 On DC, run the command: dsmod computer "cn=*compname*,ou=*dep*,dc=*dmn*,dc=*com*" -reset

    1.2 Log on to the workstation with local credentials, move the computer to workgroup, move back to domain, reboot.

    Note: replace the values for cn=, ou= and dc= to compose a proper LDIF path.

  2. Reset the workstation password with nltest command:

    2.1 Log on to the workstation with local administrator credentials

    2.2 Run the command: nltest /server:*workstationName* /sc_reset:*DC_Name*

    2.3 Reboot the workstation

  3. Reset the workstation password with Test-ComputerSecureChanel cmdlet from Powershell v3:

    3.1 Log on to the workstation with local administrator credentials

    3.2 Run in Powershell: Test-ComputerSecureChanel -Repair

    3.3 Reboot the workstation

Additional information

As the default computer password duration period is 30 days, a similar issue can be faced in case of restoration from an outdated CT or VM backup with domain membership.

You can use vzctl/prlctl command in order to automate computer account reset procedure:

vzctl exec CTID nltest /server:*workstationName* /sc_reset:*DC_Name*
vzctl restart CTID 

prlctl exec VM_NAME nltest /server:*workstationName* /sc_reset:*DC_Name*
prlctl restart VM_NAME

Related Articles

Trust Relationship Between Workstation and Domain Fails
How to fix the "Trust Relationship Between Workstation and Domain Failed" error

Search Words

Migrate Physical to PCS

windows login

trust relationship


a26b38f94253cdfbf1028d72cf3a498b 2897d76d56d2010f4e3a28f864d69223 d02f9caf3e11b191a38179103495106f 965b49118115a610e93635d21c5694a8 0dd5b9380c7d4884d77587f3eb0fa8ef

Email subscription for changes to this article
Save as PDF