RE: SIDS show instead of user names



Hi ,

This issue can occur because the SIDs in ACL are not resolved into friendly
user name immediately. Therefore, there will no access denied issue. If the
problem occur continually or always, please check if the TCP/IP NetBIOS
Helper service set to disabled on the member server. If so, please enable
it.

If the problem happens intermittently, not very frequently, I think it is
the intermittent network issue. The troubleshooting process may be
time-consuming and troublesome. However, please rest assured that I will
try my best to provide assistance.

Thanks.

Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
Thread-Topic: SIDS show instead of user names
thread-index: AcaVdane96zSt6CoQHmY7YpuCPFG0A==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
Subject: SIDS show instead of user names
Date: Wed, 21 Jun 2006 14:00:02 -0700
Lines: 23
Message-ID: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.win2000.active_directory:114528
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory

I have a Windows 2000, SP4 member server in a single 2003 AD Domain. The
machine is a file server and IIS public Web server.
I log on to the server with my domain account, which has administrator
rights on the server and when I look at either a group's membership, or
the
ACL on a folder, I see the SID rather than the user name.

It doesn't appear as though anyone is being denied access. If I add a
user
to a group or ACL, I can browse through the domain list of users, but
once
they are added and I click OK, they show as only a SID.

I get the same behavior if I try this from a remote machine, either by
using
explorer to look at ACLs or Computer Management to look at group
membership.
I tried using the showacls command line utility and as long as it is used
remotely, I DO then see the friendly names in ACLs. Also, when logged
onto
the server I can see the name of my own domain account, but it is
followed by
the SID.

This problem began to happen suddenly for no apparent reason. I see
nothing
in the Event Logs that gives any clue.

Does anyone have any suggestions about fixing this?

Thanks.


.



Relevant Pages

  • RE: SIDS show instead of user names
    ... One more thing that may or may not apply: File Server for MacIntosh is ... This issue can occur because the SIDs in ACL are not resolved into friendly ... Helper service set to disabled on the member server. ...
    (microsoft.public.win2000.active_directory)
  • [SLE] Remote Booting using SuSE AMD64 Enterprise Server 8
    ... Enterprise Server 8 for AMD64. ... I got the right linux kernel, I set up DHCP and the right TFTP (without ... The diskless nodes, on startup, immediately obtain an address from the range. ... removing the hard drive from the remote machine). ...
    (SuSE)
  • Re: Dynamic DNS and failed journal
    ... changed control clause to be updated by localhost and server ... i thought it was odd too....but in retrospect, it means to listen on 127.0.0.1 and any other NICS using 192.168.10.0/24 netowrk that may be in the box ... ... I would have thought allow-wuery would have been ok with an acl ... ... had to be done outside of the subnet clauses. ...
    (Fedora)
  • OpenSSH Problem -Please Help, Thank you!
    ... I was wondering if you could help me with an OpenSSH problem I ... Pageant machine to my Windows XP OpenSSH remote machine (email server) ... and the command prompt showed I was in my home directory ...
    (comp.security.ssh)
  • Re: Re-Post: 550 - Sender Not Allowed
    ... > I don't believe that any router ACL or routing issue could cause this problem. ... > server that has ACLs setup to allow and deny mail flow. ... > directed to the newsgroup/thread from which they originated. ... > as a mail hub for all of those domains. ...
    (microsoft.public.exchange2000.protocols)

Loading