Resolving SIDs to user names



Hi,

I'm not sure whether this topic belongs in this group, I didn't find
any better place.

Usually when I open the security tab of a file or folder the SIDs
contained in the Access Control Entries in the DACL are converted to
names - ok.

I have this scenario:
- Fileserver in Domain A, a DC for Domain A next to it
- XP client from Domain B, a DC for Domain B next to it
- a firewall seperates Domain A from Domain B, access from B to A is
open, from A to B only the DCs may talk - specifically the file server
may not talk to the DC for domain B.

When I open a share on A\Fileserver from the client and add an account
from Domain B to the DACL, that works fine. As soon as I close the
properties dialogue and re-open it, the name from Domain B can no
longer be resolved - it shows only the SID.

Now my question: which machine converts those SIDs to names? Does the
file server deliver the SIDs or the names to the client?

I hope this doesn't sound too weird, but we have some trouble
administering our file ressources, because we see only SIDs...

Any help?
Christoph

.



Relevant Pages

  • Re: Resolving SIDs to user names
    ... Client ports and server port definitions: ... Usually when I open the security tab of a file or folder the SIDs ... XP client from Domain B, a DC for Domain B next to it ... file server deliver the SIDs or the names to the client? ...
    (microsoft.public.windows.server.active_directory)
  • Re: SBS2008 / Vista x64 clients - cant join domain using wizard
    ... Acronis snap deploy is changes the SIDs on boot up, ... Many organizations use disk image cloning to perform mass rollouts of ... and configured Windows computer onto the disk drives of other computers. ... client before the client was added to the domain. ...
    (microsoft.public.windows.server.sbs)
  • Re: Determine if IdentityReference is a Security Group
    ... a User Allow is placed before a Group Deny. ... suppose I have a DACL which allows user John Doe, ... actually be granted access to read by the DACL. ... expanded list of group SIDs and all of the other built-in SIDs (like ...
    (microsoft.public.dotnet.security)
  • Re: migrating file permissions
    ... We are migrating to a NEWDOMAIN domain which is windows 2003 based. ... is a file server joined to the old domain which has a lot of shared folders ... You can do this with the Sidwalk Migration Suite, and you can even do this earlier by just adding the newdomain SIDs to the ACLs where the olddomain SIDs are, without replacing the old ones yet. ...
    (microsoft.public.windows.server.active_directory)
  • Access Token with conflicting SIDs
    ... My application is running on an Administrator group account. ... DACL so that I would be able to restore the key to it's secured state ... Anyone have any thoughts on how to clear out all the SIDs in my access ...
    (microsoft.public.platformsdk.security)

Loading