RE: SIDS show instead of user names
- From: v-xuwen@xxxxxxxxxxxxxxxxxxxx (Vincent Xu [MSFT])
- Date: Wed, 28 Jun 2006 08:08:55 GMT
Hi,
I agree with you that we may have a try to reset computer account. Please
let me know the results and I will be glad to provide assistance.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================
--------------------
<4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: SIDS show instead of user names
thread-index: AcaZ9XofwK8HzIiOS86su0jerifTqA==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
<4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx>
<AcQOcYplGHA.5184@xxxxxxxxxxxxxxxxxxxxx>
<EE786F60-D9BF-4CF6-9FDA-E524AA8600F7@xxxxxxxxxxxxx>
<l3Wv5KOmGHA.5164@xxxxxxxxxxxxxxxxxxxxx>
<2E09F3F8-6FCA-4462-ABB7-F1C7C8E72AFE@xxxxxxxxxxxxx>
<Ku5xExcmGHA.2260@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.win2000.active_directory:114651Subject: RE: SIDS show instead of user names
Date: Tue, 27 Jun 2006 07:25:02 -0700
Lines: 327
Message-ID: <F031AA96-DC93-4B13-868E-F99427C6AF42@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
theNNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory
OK, I guess it was worth running sidtoname, if only because it adds to
Eventweirdness. It gives an error and reports that the trust relationship has
failed between the domain and workstation. That makes no sense at all
because I can log on with a domain account and I can still add users to
groups and ACLs and administer remotely and there are no errors in the
server, ILogs.
If I look at the same SIDs from my own workstation using sidtoname, I can
resolve them. If I do the same, but append the name of the problem
Onceget the same error message as above.
Here is some other info:
Speaking of Event Logs, user names show as SIDs until I open an event.
Descriptionthe box opens for the event the user name shows, but only in the
asection.
This problem is not 100% consistent; once in a great while I come across
theuser name instead of a SID in a local group, but there are very few and
thename is always followed by the SID. If I add one of those users to a
different group I get the same result; I see the user name (followed by
orSID).
Maybe we can simply try removing and rejoining the machine to the domain
thatuse Netdom to reset the account (even if it doesn't appear as though it's
needed).
"Vincent Xu [MSFT]" wrote:
Hi,
Honestly, it is a weird issue. The reason I suggest you run sidname is
SIDI'd like to make sure the sid can be resolved at the same time you see
errorin ACL. Please let me know the results in detail (If there are any
somessages.)
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader
rights.that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
so======================================================
--------------------
<4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: SIDS show instead of user names
thread-index: AcaZNhcLx49xnCVqT66a1eAuT/T2Bw==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
<4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx>
<AcQOcYplGHA.5184@xxxxxxxxxxxxxxxxxxxxx>
<EE786F60-D9BF-4CF6-9FDA-E524AA8600F7@xxxxxxxxxxxxx>
<l3Wv5KOmGHA.5164@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.win2000.active_directory:114617Subject: RE: SIDS show instead of user names
Date: Mon, 26 Jun 2006 08:35:02 -0700
Lines: 321
Message-ID: <2E09F3F8-6FCA-4462-ABB7-F1C7C8E72AFE@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
136.167.2.235NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory
Vincent -
Thanks for the help. 136.167.2.233 is also a DC (we have 4).
differenthas all the domain level operations masters, but it is not a GC. A
againDC has the forest wide operations masters and the other 2 are GCs. I
want to stress that there is no WAN involved and only one AD domain,
Sincethere
wantedis plenty of connectivity with the GCs, etc.
I did not use the Sid2name tool because I got the impression that you
me to use it to confirm whether or not the accounts were deleted.
PaulI
remotelyknow the accounts were not deleted (remember, I was able to see them
using showacls), I didn't use Sid2name. See my latest response to
andBergson below. He suggested I run LDP from the server. I did that
thatwas
able to see every user name in a particular OU. If you still think
youI
Name.cap, itshould run Sid2name, let me know.
Regards.
"Vincent Xu [MSFT]" wrote:
Hi,
Thanks for sending me the trace data.
I also found that in SID.cap, it contacts 136.167.2.235 and in
136.167.2.233.contacts 136.167.2.247. However, I found in Name.cap, an IP:
What IP is this?
Since the problem seems to be related to 136.167.2.235, I suggest
youshutdown this DC temporarily to see if the problem happens again.
Also, did you see the tool sid2name I attached? I'd like to suggest
canrun
it when the problem occurs to verify at the same time, if the sid
newsreaderbe
resolved. The syntax like:
Sid2name S-1-5-21-583907252-688789844-725345543-1344
Let me know the detailed output.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
Iso
rights.that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
======================================================
--------------------
<4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: SIDS show instead of user names
thread-index: AcaW0afIQ6U8H4otSAWIo/blJC3BXA==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References: <D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>
<4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx>
<AcQOcYplGHA.5184@xxxxxxxxxxxxxxxxxxxxx>
microsoft.public.win2000.active_directory:114567Subject: RE: SIDS show instead of user names
Date: Fri, 23 Jun 2006 07:31:03 -0700
Lines: 261
Message-ID: <EE786F60-D9BF-4CF6-9FDA-E524AA8600F7@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.win2000.active_directory
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.win2000.active_directory
Thanks for the help. I may not be able to get to this today, but
thiswill becertainly
will do the NetMon trace. I was thinking of using NetMon, but it
very helpful for someone else to look at the output.
As far as the accounts being deleted in AD, keep in mind that
everyaffects
every single account (other than the one I'm logged on with) in
newACL
and
group, so I already know that isn't the problem. Even if I add a
belowaccount
to a group, that user's name disappears as soon as I click OK.
"Vincent Xu [MSFT]" wrote:
Hi,
Thanks for your reply and clarifying.
Let's perform some troubleshooting steps:
2. Please use the tool sid2name.exe tool (attached) to
determine the name of those unknown accounts. Please run the
cannot beone-by-one and
check the output:
Sid2name S-1-5-21-583907252-688789844-725345543-1344
Sid2name S-1-5-21-583907252-688789844-725345543-24842
Sid2name S-1-5-21-583907252-688789844-725345543-24843
Sid2name S-1-5-21-583907252-688789844-725345543-37443
Could you find the account names from sid2name.exe? If it
ADusernamefound,
the user
accounts are probably deleted and cause this problem. If the
can
computers tobe shown
from sid2name, please search the user accounts in AD users and
ensure
it is there.
3. If you can find the user accounts name and it is existed in
problematicusers
and
computers, please help to capture netmon trace on the
problematicfile
server.
A. Install the built-in network monitor tools on the
Componentsfile
server.
Windows 2000: (Add/Remove Program --> Add/Remove Windows
it is-->
rebootManagement
and Monitoring Tools --> Network Monitor Tools --> no need to
machine)
B. Synchronize the time between file server and DC (otherwise
card bydifficult to
check in netmon)
C. Run the netmon tool on the file server.
D. Go to Capture --> Networks to choose the correct network
sizeMAC
address
E. Go to Capture --> Buffer Settings and set 100MB as buffer
on(this
setting is
to avoid the trace overwrite itself)
F. Go to Capture --> Start to start capture the network traffic
accountboth
machines.
G. Reproduce the problem by checking the ACL.
H. Stop the capture in network monitor after the unknown
theshown.
trace)(Please
note the system time <hh:mm:ss>, we need it to check the netmon
I. Save the network trace and send to me, please also tell me
noIP of
newsreaderthe
machine.
my email is: v-xuwen@xxxxxxxxxxxxx
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your
so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers
<D97EA440-62A7-48DF-85BF-76B2082048E5@xxxxxxxxxxxxx>rights.
======================================================
--------------------
Thread-Topic: SIDS show instead of user names
thread-index: AcaWFVZsDXP9mpt8TPuuWrsXdSUfxQ==
X-WBNR-Posting-Host: 136.167.76.86
From: =?Utf-8?B?Q2hhcmxpZQ==?= <baboon@xxxxxxxxxxxxxx>
References:
<4F433889-5407-4A02-8E93-BEBE56FCB18A@xxxxxxxxxxxxx><4cAln0blGHA.4908@xxxxxxxxxxxxxxxxxxxxx>
Subject: RE: SIDS show instead of user names
Date: Thu, 22 Jun 2006 09:03:01 -0700
Lines: 117
Message-ID:
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
.
- Follow-Ups:
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- References:
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- From: Vincent Xu [MSFT]
- RE: SIDS show instead of user names
- From: Charlie
- RE: SIDS show instead of user names
- Prev by Date: Followup to DNS question
- Next by Date: Re: invalid file names
- Previous by thread: RE: SIDS show instead of user names
- Next by thread: RE: SIDS show instead of user names
- Index(es):
Relevant Pages
|