RE: SIDS show instead of user names
- From: v-xuwen@xxxxxxxxxxxxxxxxxxxx (Vincent Xu [MSFT])
- Date: Tue, 27 Jun 2006 09:15:11 GMT
Hi,
Honestly, it is a weird issue. The reason I suggest you run sidname is that
I'd like to make sure the sid can be resolved at the same time you see SID
in ACL. Please let me know the results in detail (If there are any error
messages.)
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================
--------------------
<4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: SIDS show instead of user names
thread-index: AcaZNhcLx49xnCVqT66a1eAuT/T2Bw==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
<4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx>
<AcQOcYplGHA.5184@xxxxxxxxxxxxxxxxxxxxx>
<EE786F60-D9BF-4CF6-9FDA-E524AA8600F7@xxxxxxxxxxxxx>
<l3Wv5KOmGHA.5164@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.win2000.active_directory:114617Subject: RE: SIDS show instead of user names
Date: Mon, 26 Jun 2006 08:35:02 -0700
Lines: 321
Message-ID: <2E09F3F8-6FCA-4462-ABB7-F1C7C8E72AFE@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
136.167.2.235NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory
Vincent -
Thanks for the help. 136.167.2.233 is also a DC (we have 4).
differenthas all the domain level operations masters, but it is not a GC. A
againDC has the forest wide operations masters and the other 2 are GCs. I
therewant to stress that there is no WAN involved and only one AD domain, so
wantedis plenty of connectivity with the GCs, etc.
I did not use the Sid2name tool because I got the impression that you
Ime to use it to confirm whether or not the accounts were deleted. Since
remotelyknow the accounts were not deleted (remember, I was able to see them
wasusing showacls), I didn't use Sid2name. See my latest response to Paul
Bergson below. He suggested I run LDP from the server. I did that and
Iable to see every user name in a particular OU. If you still think that
Name.cap, itshould run Sid2name, let me know.
Regards.
"Vincent Xu [MSFT]" wrote:
Hi,
Thanks for sending me the trace data.
I also found that in SID.cap, it contacts 136.167.2.235 and in
136.167.2.233.contacts 136.167.2.247. However, I found in Name.cap, an IP:
runWhat IP is this?
Since the problem seems to be related to 136.167.2.235, I suggest you
shutdown this DC temporarily to see if the problem happens again.
Also, did you see the tool sid2name I attached? I'd like to suggest you
beit when the problem occurs to verify at the same time, if the sid can
soresolved. The syntax like:
Sid2name S-1-5-21-583907252-688789844-725345543-1344
Let me know the detailed output.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader
rights.that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
will be======================================================
--------------------
<4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: SIDS show instead of user names
thread-index: AcaW0afIQ6U8H4otSAWIo/blJC3BXA==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
<4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx>
<AcQOcYplGHA.5184@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.win2000.active_directory:114567Subject: RE: SIDS show instead of user names
Date: Fri, 23 Jun 2006 07:31:03 -0700
Lines: 261
Message-ID: <EE786F60-D9BF-4CF6-9FDA-E524AA8600F7@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
certainlyNNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory
Thanks for the help. I may not be able to get to this today, but I
will do the NetMon trace. I was thinking of using NetMon, but it
ACLaffectsvery helpful for someone else to look at the output.
As far as the accounts being deleted in AD, keep in mind that this
every single account (other than the one I'm logged on with) in every
usernameand
accountgroup, so I already know that isn't the problem. Even if I add a new
found,to a group, that user's name disappears as soon as I click OK.
"Vincent Xu [MSFT]" wrote:
Hi,
Thanks for your reply and clarifying.
Let's perform some troubleshooting steps:
2. Please use the tool sid2name.exe tool (attached) to
determine the name of those unknown accounts. Please run the below
one-by-one and
check the output:
Sid2name S-1-5-21-583907252-688789844-725345543-1344
Sid2name S-1-5-21-583907252-688789844-725345543-24842
Sid2name S-1-5-21-583907252-688789844-725345543-24843
Sid2name S-1-5-21-583907252-688789844-725345543-37443
Could you find the account names from sid2name.exe? If it cannot be
the user
accounts are probably deleted and cause this problem. If the
userscan
computers tobe shown
from sid2name, please search the user accounts in AD users and
ensure
it is there.
3. If you can find the user accounts name and it is existed in AD
fileand
computers, please help to capture netmon trace on the problematic
fileserver.
A. Install the built-in network monitor tools on the problematic
-->server.
Windows 2000: (Add/Remove Program --> Add/Remove Windows Components
rebootManagement
and Monitoring Tools --> Network Monitor Tools --> no need to
MACmachine)
B. Synchronize the time between file server and DC (otherwise it is
difficult to
check in netmon)
C. Run the netmon tool on the file server.
D. Go to Capture --> Networks to choose the correct network card by
(thisaddress
E. Go to Capture --> Buffer Settings and set 100MB as buffer size
bothsetting is
to avoid the trace overwrite itself)
F. Go to Capture --> Start to start capture the network traffic on
shown.machines.
G. Reproduce the problem by checking the ACL.
H. Stop the capture in network monitor after the unknown account
trace)(Please
note the system time <hh:mm:ss>, we need it to check the netmon
IP of
I. Save the network trace and send to me, please also tell me the
newsreaderthe
machine.
my email is: v-xuwen@xxxxxxxxxxxxx
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
yes,so
rights.that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
======================================================
--------------------
<4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: SIDS show instead of user names
thread-index: AcaWFVZsDXP9mpt8TPuuWrsXdSUfxQ==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
microsoft.public.win2000.active_directory:114542Subject: RE: SIDS show instead of user names
Date: Thu, 22 Jun 2006 09:03:01 -0700
Lines: 117
Message-ID: <4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory
Hi Vincent -
Thanks for the response. The NBT Helper service is started and
openthis
waiting.problem is persistent. It is not something that is resolved by
If
I open a window for a group membership or ACL, I can leave it
Thefor 10
minutes and it still only shows SIDs.
I don't think it's a network issue and it is not intermittent.
thatreason I
don't believe it is network related is because of the following
it isI
said
in my post:
"I tried using the showacls command line utility and as long as
itloggedused
remotely, I DO then see the friendly names in ACLs. Also, when
onto the server I can see the name of my own domain account, but
MacIntoshis
followed by the SID."
One more thing that may or may not apply: File Server for
startis
supposed to be running on that server, but the service will not
instead,and
don'tboth of these problems may have started around the same time. We
really need FSM because the Mac users can connect using SMB
intobut
I
thought I should mention it for troubleshooting purposes.
Thanks.
"Vincent Xu [MSFT]" wrote:
Hi ,
This issue can occur because the SIDs in ACL are not resolved
pleaseissue. Iffriendly
user name immediately. Therefore, there will no access denied
NetBIOSthe
problem occur continually or always, please check if the TCP/IP
Helper service set to disabled on the member server. If so,
thinkenable
it.
If the problem happens intermittently, not very frequently, I
beit
is
the intermittent network issue. The troubleshooting process may
that Itime-consuming and troublesome. However, please rest assured
nonewsreaderwill
try my best to provide assistance.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers
<D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>rights.
======================================================
--------------------
Thread-Topic: SIDS show instead of user names
thread-index: AcaVdane96zSt6CoQHmY7YpuCPFG0A==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
Subject: SIDS show instead of user names
Date: Wed, 21 Jun 2006 14:00:02 -0700
Lines: 23
Message-ID:
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
.
- Follow-Ups:
- RE: SIDS show instead of user names
- From: Charlie
- Re: SIDS show instead of user names
- From: Paul Bergson
- RE: SIDS show instead of user names
- References:
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- Prev by Date: Re: recovering a DC
- Next by Date: Re: recovering a DC
- Previous by thread: RE: SIDS show instead of user names
- Next by thread: Re: SIDS show instead of user names
- Index(es):
Relevant Pages
|