RE: SIDHistory and kerberos max token size
- From: v-xuwen@xxxxxxxxxxxxxxxxxxxx (Vincent Xu [MSFT])
- Date: Wed, 27 Sep 2006 01:55:13 GMT
Hi,
Totally no relationship. As well as, it increaed the token size. You don't
need to worry about this.
Thanks.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================
--------------------
microsoft.public.windows.server.migration:25142From: "P" <p@xxxxx>
Subject: SIDHistory and kerberos max token size
Date: Tue, 26 Sep 2006 16:49:55 +0800
Lines: 27
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.2900.2869
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962
X-RFC2646: Format=Flowed; Original
Message-ID: <ueyk3iU4GHA.3400@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.windows.server.migration
NNTP-Posting-Host: 203.19.211.250
Path: TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP04.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
modifiedX-Tomcat-NG: microsoft.public.windows.server.migration
Hi
I have to migrate from one win2003 native domain to another in the same
forest. Currently, kerberos max token size on the client had to be
howbecause each user is a member of almost 1000 groups (don't ask ).
As per http://support.microsoft.com/kb/327825, max token size is 100000
An AD policy has been set to do this domain wide.
Now if I migrate the users and groups over a staged timeframe, will the
SIDHistory attribute have any negative impact on this? It doesn't change
amany groups the user is a member of, but the groups themselves will have
besid history as well as the user accounts right?
Some of sites this current domain services are remote where the resource
server is also the domain controller. Therefore the resources will still
areon a server in the old domain for a while until all the users and groups
cut over.
Will I have to be careful here? Will this catch me out?
regards
Paul
.
- References:
- Prev by Date: RE: Universal Groups
- Next by Date: RE: Security Translation on ADMT2.0 problem
- Previous by thread: SIDHistory and kerberos max token size
- Next by thread: Security Translation on ADMT2.0 problem
- Index(es):
Relevant Pages
|