SIDHistory and kerberos max token size



Hi

I have to migrate from one win2003 native domain to another in the same
forest. Currently, kerberos max token size on the client had to be modified
because each user is a member of almost 1000 groups (don't ask ).

As per http://support.microsoft.com/kb/327825, max token size is 100000

An AD policy has been set to do this domain wide.

Now if I migrate the users and groups over a staged timeframe, will the
SIDHistory attribute have any negative impact on this? It doesn't change how
many groups the user is a member of, but the groups themselves will have a
sid history as well as the user accounts right?

Some of sites this current domain services are remote where the resource
server is also the domain controller. Therefore the resources will still be
on a server in the old domain for a while until all the users and groups are
cut over.

Will I have to be careful here? Will this catch me out?

regards

Paul


.



Relevant Pages

  • Re: Users can access shares through mapped drives but not using unc
    ... Where is the 'resource' located - in the child ... Is the 'file server' on a Domain Controller or on a Member Server? ... Can you access the 'resources' when logged on as a member of the Domain ... Ping via IP Address? ...
    (microsoft.public.win2000.active_directory)
  • Re: Simple resource protection with public keys
    ... > I have a server, which holds a resource. ... Since I need these keys anyway (for another part ... > The channel between server and client is not necessarily encrypted. ...
    (sci.crypt)
  • Re: Client/Server application with single login-SecureStream?
    ... that is NOT a member of a domain? ... but I'm looking at a case where client A is a member ... of domain D, and server B is connected to the same network as A, but is ... Will B still be able to authenticate the client if it ...
    (microsoft.public.dotnet.security)
  • Re: statisches Remoting-Objekt als Hashtable key?
    ... statische Member auch bei einer MarshalByRef-Klasse immer auf den ... lokalen Rechner (Client oder Server). ... Einmal auf dem Server und einmal auf dem ...
    (microsoft.public.de.german.entwickler.dotnet.csharp)
  • Re: AD-Fu a bit rusty so a small sec question
    ... Microsoft MVP (Windows Server: Security) ... > The resourse is on a NAS, not a window member server. ... >>> My problem is now assigning that domain local group to a resource. ... not domain local group to assign permissions to a resource. ...
    (microsoft.public.win2000.security)