LDAP and Whoami.exe SIDs don't match?
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
LDAP and Whoami.exe SIDs don't match?

 
Post new topic   Reply to topic    Windows Server Forum Index -> Migration
Author Message
moparmanimal@gmail.com
Guest





Posted: Fri Sep 30, 2005 8:50 pm    Post subject: LDAP and Whoami.exe SIDs don't match? Reply with quote

Hello,

I'm migrating a Win2k native forest to a Win2k3 native forest. I'm
using ADMTv2 for the migration and am migrating with passwords and SID
history. Everything is working with the migrated accounts and computers
so far except for the built-in group: Domain Admins. Meaning email,
access to file shares, and the like are all working except any migrated
admins cannot administer computers not yet migrated (no \\machine\c$
for example). What happens is I am prompted for credentials which tells
me no SID history.

Obviously ADMT cannot migrate "Domain Admins" so I used sidhist.vbs and
it appeared to run with no errors. I verified that the SID history
attribute of Target\Domain Admins was indeed populated with the SID of
Source\Domain Admins - or is it?

When I am in the source domain logged in as myself (a memeber of Domain
Admins) and run "whoami /all" I see a SID for "Domain Admins" - in fact
the SID that in the Target Domain SidHistory attribute. When I run
getsid.exe to compare the two Source domain DC SIDs for "Domain Admins"
they match with the same SID - again the SID displayed in the target
"Domain Admins" SidHistory. HOWEVER, when I run ldp.exe and browse to
the object "Domain Admins", the "objectSid:" property shows a totally
different SID that isnt even close!

It seems to me that this must be why the SID history for "Domain
Admins" is not working but how is it that LDAP shows one SID yet the
SID showing utils (whoami and getsid) display something else?

I've searched and cannot find any info on this. Anyone have any ideas
for me?

Thanks,

Chris
Information Services
Clackamas County, OR
Back to top
Vincent Xu [MSFT]
Guest





Posted: Mon Oct 03, 2005 8:50 am    Post subject: RE: LDAP and Whoami.exe SIDs don't match? Reply with quote

Hi,

I think it is really weird that the sid is different by using whoami and
ldp. I'd like to provide the steps I do it in ldp.

1. run ldp.
2. click "connection->bind" and type Domain Administrator's username and
password.
3. click "View-Tree" and type "cn=domain admins,cn=users,dc=<your domain
name>,dc=com"
4. click OK you will find the objectsid at right column.

I'd like to suggest you follow this steps to run ldp and sending me a
screen shot to let me know the sid. As well as the screen shot of the
results of whoami

I noticed that you have logged as source domain admins to do the same
thing, please also send me the screen shots of this.

As you said the domain admins cannot access file share. Please let me know
the NTFS permissions settings and the file share permission settings. You
may also sending me the screen shots to let me know this. My mail is :
v-xuwen@microsoft.com

Looking forward for your response.

Have a good day!

Best regards,

Vincent Xu
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security


--------------------
Quote:
From: "moparmanimal@gmail.com" <moparmanimal@gmail.com
Newsgroups: microsoft.public.windows.server.migration
Subject: LDAP and Whoami.exe SIDs don't match?
Date: 30 Sep 2005 12:07:19 -0700
Organization: http://groups.google.com
Lines: 38
Message-ID: <1128107238.989982.202600@z14g2000cwz.googlegroups.com
NNTP-Posting-Host: 198.245.132.2
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Trace: posting.google.com 1128107244 25116 127.0.0.1 (30 Sep 2005
19:07:24 GMT)
X-Complaints-To: groups-abuse@google.com
NNTP-Posting-Date: Fri, 30 Sep 2005 19:07:24 +0000 (UTC)
User-Agent: G2/0.2
X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.7.10) Gecko/20050716 Firefox/1.0.6,gzip(gfe),gzip(gfe)
Complaints-To: groups-abuse@google.com
Injection-Info: z14g2000cwz.googlegroups.com; posting-host=198.245.132.2;
posting-account=RQ7K2A0AAAC-TLHh4pc43RuPRTwAR22f
Path:
TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfeed00.sul.t-online.de!t-onli

ne.de!border2.nntp.dca.giganews.com!nntp.giganews.com!postnews.google.com!z1
4g2000cwz.googlegroups.com!not-for-mail
Quote:
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:12198
X-Tomcat-NG: microsoft.public.windows.server.migration

Hello,

I'm migrating a Win2k native forest to a Win2k3 native forest. I'm
using ADMTv2 for the migration and am migrating with passwords and SID
history. Everything is working with the migrated accounts and computers
so far except for the built-in group: Domain Admins. Meaning email,
access to file shares, and the like are all working except any migrated
admins cannot administer computers not yet migrated (no \\machine\c$
for example). What happens is I am prompted for credentials which tells
me no SID history.

Obviously ADMT cannot migrate "Domain Admins" so I used sidhist.vbs and
it appeared to run with no errors. I verified that the SID history
attribute of Target\Domain Admins was indeed populated with the SID of
Source\Domain Admins - or is it?

When I am in the source domain logged in as myself (a memeber of Domain
Admins) and run "whoami /all" I see a SID for "Domain Admins" - in fact
the SID that in the Target Domain SidHistory attribute. When I run
getsid.exe to compare the two Source domain DC SIDs for "Domain Admins"
they match with the same SID - again the SID displayed in the target
"Domain Admins" SidHistory. HOWEVER, when I run ldp.exe and browse to
the object "Domain Admins", the "objectSid:" property shows a totally
different SID that isnt even close!

It seems to me that this must be why the SID history for "Domain
Admins" is not working but how is it that LDAP shows one SID yet the
SID showing utils (whoami and getsid) display something else?

I've searched and cannot find any info on this. Anyone have any ideas
for me?

Thanks,

Chris
Information Services
Clackamas County, OR

Back to top
moparmanimal@gmail.com
Guest





Posted: Mon Oct 03, 2005 4:50 pm    Post subject: Re: LDAP and Whoami.exe SIDs don't match? Reply with quote

Thanks for the response Vincent. I sent you an email as requested. If
we get it figured out I'll post the results for the benefit of everyone.
Back to top
Vincent Xu [MSFT]
Guest





Posted: Tue Oct 04, 2005 8:51 am    Post subject: Re: LDAP and Whoami.exe SIDs don't match? Reply with quote

Hi ,

I have reviewed the screen shot and actually the 2 sid is the same. The sid
displaied in ldp is the hexadecimal number.

Now we need to do is generate a SID mapping file for security translations.
Please refer to following article:

835991 How to use a SID mapping file with the ADMT tool to perform a
resource
http://support.microsoft.com/?id=835991

Hope it helps.

I will out off office from 10/5/2005 to 10/6/2005. During that time, you
can contact my backup at pngfd@microsoft.com and add following information,
they will respond you as soon as possible.

Post queue (For example: microsoft.public.server.migration)
Post tile
My name (Vincent Xu)

Have a good day.

Best regards,

Vincent Xu
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security


--------------------
Quote:
From: "moparmanimal@gmail.com" <moparmanimal@gmail.com
Newsgroups: microsoft.public.windows.server.migration
Subject: Re: LDAP and Whoami.exe SIDs don't match?
Date: 3 Oct 2005 09:35:26 -0700
Organization: http://groups.google.com
Lines: 3
Message-ID: <1128357326.556135.164540@f14g2000cwb.googlegroups.com
References: <1128107238.989982.202600@z14g2000cwz.googlegroups.com
NNTP-Posting-Host: 198.245.132.2
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Trace: posting.google.com 1128357331 25312 127.0.0.1 (3 Oct 2005
16:35:31 GMT)
X-Complaints-To: groups-abuse@google.com
NNTP-Posting-Date: Mon, 3 Oct 2005 16:35:31 +0000 (UTC)
In-Reply-To: <1128107238.989982.202600@z14g2000cwz.googlegroups.com
User-Agent: G2/0.2
X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.7.10) Gecko/20050716 Firefox/1.0.6,gzip(gfe),gzip(gfe)
Complaints-To: groups-abuse@google.com
Injection-Info: f14g2000cwb.googlegroups.com; posting-host=198.245.132.2;
posting-account=RQ7K2A0AAAC-TLHh4pc43RuPRTwAR22f
Path:
TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfeed00.sul.t-online.de!t-onli

ne.de!border2.nntp.dca.giganews.com!border1.nntp.dca.giganews.com!nntp.gigan
ews.com!postnews.google.com!f14g2000cwb.googlegroups.com!not-for-mail
Quote:
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:12217
X-Tomcat-NG: microsoft.public.windows.server.migration

Thanks for the response Vincent. I sent you an email as requested. If
we get it figured out I'll post the results for the benefit of everyone.

Back to top
moparmanimal@gmail.com
Guest





Posted: Thu Oct 06, 2005 12:51 am    Post subject: Re: LDAP and Whoami.exe SIDs don't match? Reply with quote

Hmmm... well if the SID displayed in LDap is hex and actually the
correct SID then I'm really not sure why it's not working. I'm also a
bit confused as to why building a SID mapping file would help when the
SID of the source\Domain Admins is already in the SIDHistory of
target\Domain Admins.

Could you clarify this a bit for me when you get a chance?

Thanks for all of your help,

Chris
Back to top
Vincent Xu [MSFT]
Guest





Posted: Fri Oct 07, 2005 8:51 am    Post subject: Re: LDAP and Whoami.exe SIDs don't match? Reply with quote

Hi,

I think we can take it as a workaround cause this issue seems to related to
the sidhistory. After you created the sid mapping file ,you also need to
perform a security migration via ADMT.

I also found following article for your reference:

893191 The security IDs for built-in domain groups are filtered in Windows
http://support.microsoft.com/?id=893191

Hope it helps.

Best regards,

Vincent Xu
Microsoft Online Partner Support

Get Secure! - www.microsoft.com/security


--------------------
Quote:
From: "moparmanimal@gmail.com" <moparmanimal@gmail.com
Newsgroups: microsoft.public.windows.server.migration
Subject: Re: LDAP and Whoami.exe SIDs don't match?
Date: 5 Oct 2005 16:34:27 -0700
Organization: http://groups.google.com
Lines: 12
Message-ID: <1128555267.075786.261750@g43g2000cwa.googlegroups.com
References: <1128107238.989982.202600@z14g2000cwz.googlegroups.com
1128357326.556135.164540@f14g2000cwb.googlegroups.com
8xNYjZKyFHA.3032@TK2MSFTNGXA01.phx.gbl
NNTP-Posting-Host: 198.245.132.2
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
X-Trace: posting.google.com 1128555272 4659 127.0.0.1 (5 Oct 2005
23:34:32 GMT)
X-Complaints-To: groups-abuse@google.com
NNTP-Posting-Date: Wed, 5 Oct 2005 23:34:32 +0000 (UTC)
In-Reply-To: <8xNYjZKyFHA.3032@TK2MSFTNGXA01.phx.gbl
User-Agent: G2/0.2
X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.7.10) Gecko/20050716 Firefox/1.0.6,gzip(gfe),gzip(gfe)
Complaints-To: groups-abuse@google.com
Injection-Info: g43g2000cwa.googlegroups.com; posting-host=198.245.132.2;
posting-account=RQ7K2A0AAAC-TLHh4pc43RuPRTwAR22f
Path:
TK2MSFTNGXA01.phx.gbl!TK2MSFTNGP08.phx.gbl!newsfeed00.sul.t-online.de!t-onli

ne.de!border2.nntp.dca.giganews.com!nntp.giganews.com!postnews.google.com!g4
3g2000cwa.googlegroups.com!not-for-mail
Quote:
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:12251
X-Tomcat-NG: microsoft.public.windows.server.migration

Hmmm... well if the SID displayed in LDap is hex and actually the
correct SID then I'm really not sure why it's not working. I'm also a
bit confused as to why building a SID mapping file would help when the
SID of the source\Domain Admins is already in the SIDHistory of
target\Domain Admins.

Could you clarify this a bit for me when you get a chance?

Thanks for all of your help,

Chris

Back to top
moparmanimal@gmail.com
Guest





Posted: Fri Oct 07, 2005 8:50 pm    Post subject: Re: LDAP and Whoami.exe SIDs don't match? Reply with quote

Ok - I'll give it a try and post the results. Incidentally I do already
have SID filtering turned off at the trusts - I don't think I mentioned
that before.

Thanks again for your help,
Chris
Back to top
moparmanimal@gmail.com
Guest





Posted: Tue Oct 11, 2005 4:51 pm    Post subject: Re: LDAP and Whoami.exe SIDs don't match? Reply with quote

I set up the SID mapping file and ran the security translation wizard
against a workstation in the source domain using the sid mapping file.
I still could not get to the admin share or any other resouce locked
down with the Domain Admins group from the target domain. Everything
I've researched and tested is telling me that it should be working -
but it doesn't. Unless there's something obvious that I'm doing wrong,
I think I'm going to move on to other issues and simply work around
this one.

Thanks for your help Vincent,
Chris
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Migration All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB