MVPs II: Back into the domain (and thread) using the same SID

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Jim Carlock (anonymous_at_127.0.0.1)
Date: 03/23/04

  • Next message: Ron Sparks: "More DNS issues Help!!"
    Date: Mon, 22 Mar 2004 22:07:15 -0500
    
    

    Just when you thought it was safe to delete the thread. This post is
    OnT.

    ;-)

    This involves an XP machine that has an SID created on a Win2K
    domain. It used to be that this machine could log in and access the
    domain in two different logon variations. And I think I know how to
    correct the problem, and am looking for any and all comments.

    NetDiag on the XP machine reports that the XP machine is getting a
    proper IP address, is getting the proper domain name suffix, but has
    an improper SID. NAT/Routing is working.

    I'm attaching the NetDiag as a text document. It displays the current
    SID problem.

    There are currently two SID's created. One is used when the
    machine is not logged onto the domain. I was in the past able to get
    the machine to hook back up into the domain but I don't know what
    I did to get it to work. One SID is used when the machine logs onto
    the domain. Now, I'm thinking that I can change the SID when it's
    not logged in, to machine that SID when it is logged in. And once
    that is done, the SID problem should go away.

    That is not completely why I'm posting though. I'm wondering if
    something has changed in the past 9 months that might be affecting
    the way clients are logging into the domain. I'm wondering if I
    secured the domain too much and am looking for any suggestions
    at all.

    This machine used to have access to the domain using two
    different SIDs and now it doesn't seem possible to do this any
    longer. Even when I set up a trust relationship, the domain seems
    to be rejecting this computer's attempt to log into the domain.

    It's almost like I'm seeing that the SID doesn't belong to the user
    any longer, but belongs to the machine now. I'm slightly confused
    about what an SID really is these days.

    -- 
    Jim Carlock
    http://www.microcosmotalk.com/
    Post replies to the newsgroup.
    begin 666 MachXP.txt
    M061A<'1E<B Z($QO8V%L($%R96$@0V]N;F5C=&EO;@T*($YE=&-A<F0@<75E
    M<FEE<R!T97-T("X@+B N(#H@4&%S<V5D#0H@2&]S="!.86UE+B N("X@+B N
    M("X@+B N("X@.B!-86-H6% N9FPN;6EC<F]C;W-M;W1A;&LN8V]M#0H@25 @
    M061D<F5S<R N("X@+B N("X@+B N("X@.B Q,"XQ,"XQ+C(-"B!3=6)N970@
    M36%S:RX@+B N("X@+B N("X@+B Z(#(U-2XR-34N,C4U+C(T. T*($1E9F%U
    M;'0@1V%T97=A>2X@+B N("X@+B N(#H@,3 N,3 N,2XQ#0H@4')I;6%R>2!7
    M24Y3(%-E<G9E<BX@+B N("X@.B Q,"XQ,"XQ+C$-"B!$;G,@4V5R=F5R<RX@
    M+B N("X@+B N("X@+B Z(#$P+C$P+C$N,0T*#0I#;VUP=71E<B!.86UE.B!-
    M86-H6% -"D1.4R!(;W-T($YA;64Z($UA8VA84"YF;"YM:6-R;V-O<VUO=&%L
    M:RYC;VT-"E-Y<W1E;2!I;F9O(#H@5VEN9&]W<R R,# P(%!R;V9E<W-I;VYA
    M;" H0G5I;&0@,C8P,"D-"E!R;V-E<W-O<B Z('@X-B!&86UI;'D@-B!-;V1E
    M;" X(%-T97!P:6YG(#$L($%U=&AE;G1I8T%-1 T*#0I.971"5"!T<F%N<W!O
    M<G1S('1E<W0N("X@+B N("X@+B N(#H@4&%S<V5D#0H@($QI<W0@;V8@3F5T
    M0G0@=')A;G-P;W)T<R!C=7)R96YT;'D@8V]N9FEG=7)E9#H-"B @(" @($YE
    M=$)47U1C<&EP7WLT,T8R,3$T,RTV13A!+3$R1$8M0S=!,BTY,D)",D8Y,#$R
    M,S1]#0H@(#$@3F5T0G0@=')A;G-P;W)T(&-U<G)E;G1L>2!C;VYF:6=U<F5D
    M+@T*075T;VYE="!A9&1R97-S('1E<W0@+B N("X@+B N("X@+B Z(%!A<W-E
    M9 T*25 @;&]O<&)A8VL@<&EN9R!T97-T+B N("X@+B N("X@+B Z(%!A<W-E
    M9 T*1&5F875L="!G871E=V%Y('1E<W0@+B N("X@+B N("X@+B Z(%!A<W-E
    M9 T*3F5T0E0@;F%M92!T97-T+B N("X@+B N("X@+B N("X@+B Z(%!A<W-E
    M9 T*5VEN<V]C:R!T97-T("X@+B N("X@+B N("X@+B N("X@+B Z(%!A<W-E
    M9 T*1$Y3('1E<W0@+B N("X@+B N("X@+B N("X@+B N("X@+B Z(%!A<W-E
    M9 T*4F5D:7(@86YD($)R;W=S97(@=&5S=" N("X@+B N("X@+B Z(%!A<W-E
    M9 T*("!,:7-T(&]F($YE=$)T('1R86YS<&]R=',@8W5R<F5N=&QY(&)O=6YD
    M('1O('1H92!2961I<@T*(" @(" @3F5T0E1?5&-P:7!?>S0S1C(Q,30S+39%
    M.$$M,3)$1BU#-T$R+3DR0D(R1CDP,3(S-'T-"B @5&AE(')E9&ER(&ES(&)O
    M=6YD('1O(#$@3F5T0G0@=')A;G-P;W)T+@T*("!,:7-T(&]F($YE=$)T('1R
    M86YS<&]R=',@8W5R<F5N=&QY(&)O=6YD('1O('1H92!B<F]W<V5R#0H@(" @
    M("!.971"5%]48W!I<%][-#-&,C$Q-#,M-D4X02TQ,D1&+4,W03(M.3)"0C)&
    M.3 Q,C,T?0T*("!4:&4@8G)O=W-E<B!I<R!B;W5N9"!T;R Q($YE=$)T('1R
    M86YS<&]R="X-"D1#(&1I<V-O=F5R>2!T97-T+B N("X@+B N("X@+B N("X@
    M.B!087-S960-"D1#(&QI<W0@=&5S=" N("X@+B N("X@+B N("X@+B N("X@
    M.B!&86EL960-"E1R=7-T(')E;&%T:6]N<VAI<"!T97-T+B N("X@+B N("X@
    M.B!&86EL960-"B @6U=!4DY)3D==($1O;B=T(&AA=F4@86-C97-S('1O('1E
    M<W0@>6]U<B!D;VUA:6X@<VED(&9O<B!D;VUA:6X@)T9,)RX-"B @(" @(%M4
    M97-T('-K:7!P961=#0H@(%M&051!3%T@4V5C=7)E(&-H86YN96P@=&\@9&]M
    M86EN("=&3"<@:7,@8G)O:V5N+B!;15)23U)?04-#15-37T1%3DE%1%T-"DME
    M<F)E<F]S('1E<W0N("X@+B N("X@+B N("X@+B N("X@.B!3:VEP<&5D#0I,
    M1$%0('1E<W0N("X@+B N("X@+B N("X@+B N("X@+B N(#H@4&%S<V5D#0H@
    M(%M705).24Y'72!9;W4@87)E(&QO9V=E9"!O;B!A<R!A(&QO8V%L('5S97(N
    M("A-86-H6%!<57-E<C$I#0H@(" @("!#86YN;W0@=&5S="!.5$Q-($%U=&AE
    M;G1I8V%T:6]N('1O("=D8RYF;"YM:6-R;V-O<VUO=&%L:RYC;VTG+@T*("!;
    M5T%23DE.1UT@1F%I;&5D('1O('%U97)Y(%-03B!R96=I<W1R871I;VX@;VX@
    M1$,@)V1C+F9L+FUI8W)O8V]S;6]T86QK+F-O;2<N#0I":6YD:6YG<R!T97-T
    M+B N("X@+B N("X@+B N("X@+B N(#H@4&%S<V5D#0I704X@8V]N9FEG=7)A
    M=&EO;B!T97-T("X@+B N("X@+B N(#H@4VMI<'!E9 T*(" @($YO(&%C=&EV
    M92!R96UO=&4@86-C97-S(&-O;FYE8W1I;VYS+@T*36]D96T@9&EA9VYO<W1I
    M8W,@=&5S=" N("X@+B N("X@+B Z(%!A<W-E9 T*#0HB9FP@:7,@;F]T(&%C
    M8V5S<VEB;&4N(%EO=2!M:6=H="!N;W0@:&%V92!P97)M:7-S:6]N('1O('5S
    M92!T:&ES#0IN971W;W)K(')E<V]U<F-E+B!#;VYT86-T('1H92!A9&UI;FES
    M=')A=&]R(&]F('1H:7,@<V5R=F5R('1O#0IF:6YD(&]U="!I9B!Y;W4@:&%V
    M92!A8V-E<W,@<&5R;6ES<VEO;G,N#0H-"E1H92!R969E<F5N8V5D(&%C8V]U
    M;G0@:7,@8W5R<F5N=&QY(&QO8VME9"!O=70@86YD(&UA>2!N;W0@8F4-"FQO
    09V=E9"!O;B!T;RXB#0H-"@``
    `
    end
    

  • Next message: Ron Sparks: "More DNS issues Help!!"

    Relevant Pages

    • Re: lost computer account
      ... I believe this is a sid problem. ... same Security Identifier and as far as the domain knows they are all ... Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA ...
      (microsoft.public.windows.server.active_directory)
    • Re: lost computer account
      ... I did not walk the sid. ... > I believe this is a sid problem. ... > same Security Identifier and as far as the domain knows they are all ...
      (microsoft.public.windows.server.active_directory)
    • RE: The SID question?!
      ... then run Sysinternals' NewSID on all of the desktops. ... that of 'administrative shares' giving access to ANY HD on the LAN ... Is there just one computer sid or is there a computer sid and a domain sid ... Does the SID problem only occur if I pulled down a image that was still ...
      (microsoft.public.windowsxp.security_admin)
    • The SID question?!
      ... bootfloppy. ... Ghostwalker etc was not used. ... Is there just one computer sid or is there a computer sid and a domain sid ... Does the SID problem only occur if I pulled down a image that was still ...
      (microsoft.public.windowsxp.security_admin)
    • Re: The spinoza papers: towards a theory of progress reporting
      ... Quertyuiop, you do not belong ... Another "keep out of my seat" demand. ... SELECT sid FROM sessions WHERE sid = ...
      (comp.programming)