Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Migration > SID filter between a W2k and a W2k Domain

Reply
Thread Tools Display Modes

SID filter between a W2k and a W2k Domain

 
 
Thorsten
Guest
Posts: n/a

 
      09-22-2008
Hello,


We are planning to do inter-forest users and group migration. Now we have a
trust between the W2k and the W2k8 Domain. The SID Filter on the W2k Domain
ist eneabled and if we use the comannd "Netdom TRUST <TrustingDomain>
/domain:<TrustedDomain> /FilterSIDs:No /userD:<domainadminAcct>
/passwordD:<domainadminpwd>", we got a "Access Denied". The user on both
Domains are Domain- /Enterprise Admins. How can we disable the SID-filter
between a W2k and a W2k8 inter-forest trust?

Thanks.

Thorsten


 
Reply With Quote
 
 
 
 
Meinolf Weber
Guest
Posts: n/a

 
      09-22-2008
Hello Thorsten,

What output comes with this command:

Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no /usero:useraccount/passwordoassword

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello,
>
> We are planning to do inter-forest users and group migration. Now we
> have a trust between the W2k and the W2k8 Domain. The SID Filter on
> the W2k Domain ist eneabled and if we use the comannd "Netdom TRUST
> <TrustingDomain> /domain:<TrustedDomain> /FilterSIDs:No
> /userD:<domainadminAcct> /passwordD:<domainadminpwd>", we got a
> "Access Denied". The user on both Domains are Domain- /Enterprise
> Admins. How can we disable the SID-filter between a W2k and a W2k8
> inter-forest trust?
>
> Thanks.
>
> Thorsten
>



 
Reply With Quote
 
Thorsten
Guest
Posts: n/a

 
      09-22-2008
Hello Meinolf,
I got a "Access denied"

If I insert a wrong password I got the message "password wrong" The user
has Domain/Enterprise Adminrights. The DNS settings are correct, I can make
a nslookup for the destination domain on the source domain.

Best regards

Thorsten
"Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
news:. com...
> Hello Thorsten,
>
> What output comes with this command:
>
> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
> /usero:useraccount/passwordoassword
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> Hello,
>>
>> We are planning to do inter-forest users and group migration. Now we
>> have a trust between the W2k and the W2k8 Domain. The SID Filter on
>> the W2k Domain ist eneabled and if we use the comannd "Netdom TRUST
>> <TrustingDomain> /domain:<TrustedDomain> /FilterSIDs:No
>> /userD:<domainadminAcct> /passwordD:<domainadminpwd>", we got a
>> "Access Denied". The user on both Domains are Domain- /Enterprise
>> Admins. How can we disable the SID-filter between a W2k and a W2k8
>> inter-forest trust?
>>
>> Thanks.
>>
>> Thorsten
>>

>
>



 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      09-22-2008
Hello Thorsten,

Have a look on this posting if you are using ADMT or NetIQ DMA and Quest
Migration Manager tools:
http://www.petri.co.il/forums/showthread.php?t=26101

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello Meinolf,
> I got a "Access denied"
> If I insert a wrong password I got the message "password wrong" The
> user has Domain/Enterprise Adminrights. The DNS settings are correct,
> I can make a nslookup for the destination domain on the source domain.
>
> Best regards
>
> Thorsten
> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
> news:. com...
>> Hello Thorsten,
>>
>> What output comes with this command:
>>
>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
>> /usero:useraccount/passwordoassword
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> Hello,
>>>
>>> We are planning to do inter-forest users and group migration. Now we
>>> have a trust between the W2k and the W2k8 Domain. The SID Filter on
>>> the W2k Domain ist eneabled and if we use the comannd "Netdom TRUST
>>> <TrustingDomain> /domain:<TrustedDomain> /FilterSIDs:No
>>> /userD:<domainadminAcct> /passwordD:<domainadminpwd>", we got a
>>> "Access Denied". The user on both Domains are Domain- /Enterprise
>>> Admins. How can we disable the SID-filter between a W2k and a W2k8
>>> inter-forest trust?
>>>
>>> Thanks.
>>>
>>> Thorsten
>>>



 
Reply With Quote
 
Thorsten
Guest
Posts: n/a

 
      09-22-2008
Hello Meinolf,

I found this acrticle this morning, too.

I had have do all Points from Akila without the Point 5. I had only a one
way trust from the W2k to the W2k8 Domain. Now I have changed the
configuration and I have a bidirectional trust between the domains. On the
Point 6 of the Posting I should diable the SID Filter, but this does not
work at my environment.

I found a posting that it could be the netdom version on the W2k DC, but the
netdom version from the W2k8 does not work on the W2k DC.

Kind regards

Thorsten

"Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
news:. com...
> Hello Thorsten,
>
> Have a look on this posting if you are using ADMT or NetIQ DMA and Quest
> Migration Manager tools:
> http://www.petri.co.il/forums/showthread.php?t=26101
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> Hello Meinolf,
>> I got a "Access denied"
>> If I insert a wrong password I got the message "password wrong" The
>> user has Domain/Enterprise Adminrights. The DNS settings are correct,
>> I can make a nslookup for the destination domain on the source domain.
>>
>> Best regards
>>
>> Thorsten
>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>> news:. com...
>>> Hello Thorsten,
>>>
>>> What output comes with this command:
>>>
>>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
>>> /usero:useraccount/passwordoassword
>>>
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>> Hello,
>>>>
>>>> We are planning to do inter-forest users and group migration. Now we
>>>> have a trust between the W2k and the W2k8 Domain. The SID Filter on
>>>> the W2k Domain ist eneabled and if we use the comannd "Netdom TRUST
>>>> <TrustingDomain> /domain:<TrustedDomain> /FilterSIDs:No
>>>> /userD:<domainadminAcct> /passwordD:<domainadminpwd>", we got a
>>>> "Access Denied". The user on both Domains are Domain- /Enterprise
>>>> Admins. How can we disable the SID-filter between a W2k and a W2k8
>>>> inter-forest trust?
>>>>
>>>> Thanks.
>>>>
>>>> Thorsten
>>>>

>
>



 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      09-22-2008
Hello Thorsten,

Try out the 2003 tools:
http://download.microsoft.com/downlo...ls-x86-ENU.exe

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello Meinolf,
>
> I found this acrticle this morning, too.
>
> I had have do all Points from Akila without the Point 5. I had only a
> one way trust from the W2k to the W2k8 Domain. Now I have changed the
> configuration and I have a bidirectional trust between the domains. On
> the Point 6 of the Posting I should diable the SID Filter, but this
> does not work at my environment.
>
> I found a posting that it could be the netdom version on the W2k DC,
> but the netdom version from the W2k8 does not work on the W2k DC.
>
> Kind regards
>
> Thorsten
>
> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
> news:. com...
>
>> Hello Thorsten,
>>
>> Have a look on this posting if you are using ADMT or NetIQ DMA and
>> Quest Migration Manager tools:
>> http://www.petri.co.il/forums/showthread.php?t=26101
>>
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> Hello Meinolf,
>>> I got a "Access denied"
>>> If I insert a wrong password I got the message "password wrong" The
>>> user has Domain/Enterprise Adminrights. The DNS settings are
>>> correct,
>>> I can make a nslookup for the destination domain on the source
>>> domain.
>>> Best regards
>>>
>>> Thorsten
>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>> news:. com...
>>>> Hello Thorsten,
>>>>
>>>> What output comes with this command:
>>>>
>>>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
>>>> /usero:useraccount/passwordoassword
>>>>
>>>> Best regards
>>>>
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>> and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> Hello,
>>>>>
>>>>> We are planning to do inter-forest users and group migration. Now
>>>>> we have a trust between the W2k and the W2k8 Domain. The SID
>>>>> Filter on the W2k Domain ist eneabled and if we use the comannd
>>>>> "Netdom TRUST <TrustingDomain> /domain:<TrustedDomain>
>>>>> /FilterSIDs:No /userD:<domainadminAcct>
>>>>> /passwordD:<domainadminpwd>", we got a "Access Denied". The user
>>>>> on both Domains are Domain- /Enterprise Admins. How can we disable
>>>>> the SID-filter between a W2k and a W2k8 inter-forest trust?
>>>>>
>>>>> Thanks.
>>>>>
>>>>> Thorsten
>>>>>



 
Reply With Quote
 
Thorsten
Guest
Posts: n/a

 
      09-22-2008
I got a error meesage that a procedure is wrong on the kernel32.dll. I could
not/should not replace the dll, or not? ;-)
"Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
news:. com...
> Hello Thorsten,
>
> Try out the 2003 tools:
> http://download.microsoft.com/downlo...ls-x86-ENU.exe
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> Hello Meinolf,
>>
>> I found this acrticle this morning, too.
>>
>> I had have do all Points from Akila without the Point 5. I had only a
>> one way trust from the W2k to the W2k8 Domain. Now I have changed the
>> configuration and I have a bidirectional trust between the domains. On
>> the Point 6 of the Posting I should diable the SID Filter, but this
>> does not work at my environment.
>>
>> I found a posting that it could be the netdom version on the W2k DC,
>> but the netdom version from the W2k8 does not work on the W2k DC.
>>
>> Kind regards
>>
>> Thorsten
>>
>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>> news:. com...
>>
>>> Hello Thorsten,
>>>
>>> Have a look on this posting if you are using ADMT or NetIQ DMA and
>>> Quest Migration Manager tools:
>>> http://www.petri.co.il/forums/showthread.php?t=26101
>>>
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>> Hello Meinolf,
>>>> I got a "Access denied"
>>>> If I insert a wrong password I got the message "password wrong" The
>>>> user has Domain/Enterprise Adminrights. The DNS settings are
>>>> correct,
>>>> I can make a nslookup for the destination domain on the source
>>>> domain.
>>>> Best regards
>>>>
>>>> Thorsten
>>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>>> news:. com...
>>>>> Hello Thorsten,
>>>>>
>>>>> What output comes with this command:
>>>>>
>>>>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
>>>>> /usero:useraccount/passwordoassword
>>>>>
>>>>> Best regards
>>>>>
>>>>> Meinolf Weber
>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>> and
>>>>> confers no rights.
>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>> Hello,
>>>>>>
>>>>>> We are planning to do inter-forest users and group migration. Now
>>>>>> we have a trust between the W2k and the W2k8 Domain. The SID
>>>>>> Filter on the W2k Domain ist eneabled and if we use the comannd
>>>>>> "Netdom TRUST <TrustingDomain> /domain:<TrustedDomain>
>>>>>> /FilterSIDs:No /userD:<domainadminAcct>
>>>>>> /passwordD:<domainadminpwd>", we got a "Access Denied". The user
>>>>>> on both Domains are Domain- /Enterprise Admins. How can we disable
>>>>>> the SID-filter between a W2k and a W2k8 inter-forest trust?
>>>>>>
>>>>>> Thanks.
>>>>>>
>>>>>> Thorsten
>>>>>>

>
>



 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      09-22-2008
Hello Thorsten,

For Windows 2000 use this example (the RESDOM domain is filtering the ACCDOM
domain):

Check out this one to disable SID filtering:
netdom trust RESDOM /D:ACCDOM /UD:ACCDOM\Administrator /PD:adminpwd /UO:RESDOM\Administrator
/PO:adminpwd /filtersids:no


Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> I got a error meesage that a procedure is wrong on the kernel32.dll. I
> could
> not/should not replace the dll, or not? ;-)
> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
> news:. com...
>> Hello Thorsten,
>>
>> Try out the 2003 tools:
>> http://download.microsoft.com/downlo...4ef-4637-abd1-
>> 981341d349c7/WindowsServer2003-KB892777-SupportTools-x86-ENU.exe
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> Hello Meinolf,
>>>
>>> I found this acrticle this morning, too.
>>>
>>> I had have do all Points from Akila without the Point 5. I had only
>>> a one way trust from the W2k to the W2k8 Domain. Now I have changed
>>> the configuration and I have a bidirectional trust between the
>>> domains. On the Point 6 of the Posting I should diable the SID
>>> Filter, but this does not work at my environment.
>>>
>>> I found a posting that it could be the netdom version on the W2k DC,
>>> but the netdom version from the W2k8 does not work on the W2k DC.
>>>
>>> Kind regards
>>>
>>> Thorsten
>>>
>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>> news:. com...
>>>
>>>> Hello Thorsten,
>>>>
>>>> Have a look on this posting if you are using ADMT or NetIQ DMA and
>>>> Quest Migration Manager tools:
>>>> http://www.petri.co.il/forums/showthread.php?t=26101
>>>>
>>>> Best regards
>>>>
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>> and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> Hello Meinolf,
>>>>> I got a "Access denied"
>>>>> If I insert a wrong password I got the message "password wrong"
>>>>> The
>>>>> user has Domain/Enterprise Adminrights. The DNS settings are
>>>>> correct,
>>>>> I can make a nslookup for the destination domain on the source
>>>>> domain.
>>>>> Best regards
>>>>> Thorsten
>>>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>>>> news:. com...
>>>>>> Hello Thorsten,
>>>>>>
>>>>>> What output comes with this command:
>>>>>>
>>>>>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
>>>>>> /usero:useraccount/passwordoassword
>>>>>>
>>>>>> Best regards
>>>>>>
>>>>>> Meinolf Weber
>>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>>> and
>>>>>> confers no rights.
>>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>>> ** HELP us help YOU!!!
>>>>>> http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>>> Hello,
>>>>>>>
>>>>>>> We are planning to do inter-forest users and group migration.
>>>>>>> Now we have a trust between the W2k and the W2k8 Domain. The SID
>>>>>>> Filter on the W2k Domain ist eneabled and if we use the comannd
>>>>>>> "Netdom TRUST <TrustingDomain> /domain:<TrustedDomain>
>>>>>>> /FilterSIDs:No /userD:<domainadminAcct>
>>>>>>> /passwordD:<domainadminpwd>", we got a "Access Denied". The user
>>>>>>> on both Domains are Domain- /Enterprise Admins. How can we
>>>>>>> disable the SID-filter between a W2k and a W2k8 inter-forest
>>>>>>> trust?
>>>>>>>
>>>>>>> Thanks.
>>>>>>>
>>>>>>> Thorsten
>>>>>>>



 
Reply With Quote
 
Thorsten
Guest
Posts: n/a

 
      09-22-2008
Hello Meinolf,

sorry, I used this parameter "FilterSIDs:no", because this netdom version
did not understand the other parameter. But what should I say: I got the
message "Access denied".
"Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
news:. com...
> Hello Thorsten,
>
> For Windows 2000 use this example (the RESDOM domain is filtering the
> ACCDOM domain):
> Check out this one to disable SID filtering: netdom trust RESDOM /D:ACCDOM
> /UD:ACCDOM\Administrator /PD:adminpwd /UO:RESDOM\Administrator
> /PO:adminpwd /filtersids:no
>
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and
> confers no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>> I got a error meesage that a procedure is wrong on the kernel32.dll. I
>> could
>> not/should not replace the dll, or not? ;-)
>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>> news:. com...
>>> Hello Thorsten,
>>>
>>> Try out the 2003 tools:
>>> http://download.microsoft.com/downlo...4ef-4637-abd1-
>>> 981341d349c7/WindowsServer2003-KB892777-SupportTools-x86-ENU.exe
>>> Best regards
>>>
>>> Meinolf Weber
>>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>>> confers no rights.
>>> ** Please do NOT email, only reply to Newsgroups
>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>> Hello Meinolf,
>>>>
>>>> I found this acrticle this morning, too.
>>>>
>>>> I had have do all Points from Akila without the Point 5. I had only
>>>> a one way trust from the W2k to the W2k8 Domain. Now I have changed
>>>> the configuration and I have a bidirectional trust between the
>>>> domains. On the Point 6 of the Posting I should diable the SID
>>>> Filter, but this does not work at my environment.
>>>>
>>>> I found a posting that it could be the netdom version on the W2k DC,
>>>> but the netdom version from the W2k8 does not work on the W2k DC.
>>>>
>>>> Kind regards
>>>>
>>>> Thorsten
>>>>
>>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>>> news:. com...
>>>>
>>>>> Hello Thorsten,
>>>>>
>>>>> Have a look on this posting if you are using ADMT or NetIQ DMA and
>>>>> Quest Migration Manager tools:
>>>>> http://www.petri.co.il/forums/showthread.php?t=26101
>>>>>
>>>>> Best regards
>>>>>
>>>>> Meinolf Weber
>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>> and
>>>>> confers no rights.
>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>> Hello Meinolf,
>>>>>> I got a "Access denied"
>>>>>> If I insert a wrong password I got the message "password wrong"
>>>>>> The
>>>>>> user has Domain/Enterprise Adminrights. The DNS settings are
>>>>>> correct,
>>>>>> I can make a nslookup for the destination domain on the source
>>>>>> domain.
>>>>>> Best regards
>>>>>> Thorsten
>>>>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>>>>> news:. com...
>>>>>>> Hello Thorsten,
>>>>>>>
>>>>>>> What output comes with this command:
>>>>>>>
>>>>>>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN /quarantine:no
>>>>>>> /usero:useraccount/passwordoassword
>>>>>>>
>>>>>>> Best regards
>>>>>>>
>>>>>>> Meinolf Weber
>>>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>>>> and
>>>>>>> confers no rights.
>>>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>>>> ** HELP us help YOU!!!
>>>>>>> http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>>>> Hello,
>>>>>>>>
>>>>>>>> We are planning to do inter-forest users and group migration.
>>>>>>>> Now we have a trust between the W2k and the W2k8 Domain. The SID
>>>>>>>> Filter on the W2k Domain ist eneabled and if we use the comannd
>>>>>>>> "Netdom TRUST <TrustingDomain> /domain:<TrustedDomain>
>>>>>>>> /FilterSIDs:No /userD:<domainadminAcct>
>>>>>>>> /passwordD:<domainadminpwd>", we got a "Access Denied". The user
>>>>>>>> on both Domains are Domain- /Enterprise Admins. How can we
>>>>>>>> disable the SID-filter between a W2k and a W2k8 inter-forest
>>>>>>>> trust?
>>>>>>>>
>>>>>>>> Thanks.
>>>>>>>>
>>>>>>>> Thorsten
>>>>>>>>

>
>



 
Reply With Quote
 
Meinolf Weber
Guest
Posts: n/a

 
      09-22-2008
Hello Thorsten,

RESDOM is resource domain and ACCDOM the other one. Check out this article
about the needed rights for enabling and also disabling SID filtering in
the domain:
http://technet.microsoft.com/en-us/l.../cc773319.aspx


Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hello Meinolf,
>
> sorry, I used this parameter "FilterSIDs:no", because this netdom
> version
> did not understand the other parameter. But what should I say: I got
> the
> message "Access denied".
> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
> news:. com...
>> Hello Thorsten,
>>
>> For Windows 2000 use this example (the RESDOM domain is filtering the
>> ACCDOM domain):
>> Check out this one to disable SID filtering: netdom trust RESDOM
>> /D:ACCDOM
>> /UD:ACCDOM\Administrator /PD:adminpwd /UO:RESDOM\Administrator
>> /PO:adminpwd /filtersids:no
>> Best regards
>>
>> Meinolf Weber
>> Disclaimer: This posting is provided "AS IS" with no warranties, and
>> confers no rights.
>> ** Please do NOT email, only reply to Newsgroups
>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>> I got a error meesage that a procedure is wrong on the kernel32.dll.
>>> I
>>> could
>>> not/should not replace the dll, or not? ;-)
>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>> news:. com...
>>>> Hello Thorsten,
>>>>
>>>> Try out the 2003 tools:
>>>> http://download.microsoft.com/downlo...-24ef-4637-abd
>>>> 1-
>>>> 981341d349c7/WindowsServer2003-KB892777-SupportTools-x86-ENU.exe
>>>> Best regards
>>>> Meinolf Weber
>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>> and
>>>> confers no rights.
>>>> ** Please do NOT email, only reply to Newsgroups
>>>> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>> Hello Meinolf,
>>>>>
>>>>> I found this acrticle this morning, too.
>>>>>
>>>>> I had have do all Points from Akila without the Point 5. I had
>>>>> only a one way trust from the W2k to the W2k8 Domain. Now I have
>>>>> changed the configuration and I have a bidirectional trust between
>>>>> the domains. On the Point 6 of the Posting I should diable the SID
>>>>> Filter, but this does not work at my environment.
>>>>>
>>>>> I found a posting that it could be the netdom version on the W2k
>>>>> DC, but the netdom version from the W2k8 does not work on the W2k
>>>>> DC.
>>>>>
>>>>> Kind regards
>>>>>
>>>>> Thorsten
>>>>>
>>>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>>>> news:. com...
>>>>>
>>>>>> Hello Thorsten,
>>>>>>
>>>>>> Have a look on this posting if you are using ADMT or NetIQ DMA
>>>>>> and Quest Migration Manager tools:
>>>>>> http://www.petri.co.il/forums/showthread.php?t=26101
>>>>>>
>>>>>> Best regards
>>>>>>
>>>>>> Meinolf Weber
>>>>>> Disclaimer: This posting is provided "AS IS" with no warranties,
>>>>>> and
>>>>>> confers no rights.
>>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>>> ** HELP us help YOU!!!
>>>>>> http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>>> Hello Meinolf,
>>>>>>> I got a "Access denied"
>>>>>>> If I insert a wrong password I got the message "password wrong"
>>>>>>> The
>>>>>>> user has Domain/Enterprise Adminrights. The DNS settings are
>>>>>>> correct,
>>>>>>> I can make a nslookup for the destination domain on the source
>>>>>>> domain.
>>>>>>> Best regards
>>>>>>> Thorsten
>>>>>>> "Meinolf Weber" <meiweb(nospam)@gmx.de> schrieb im Newsbeitrag
>>>>>>> news:. com...
>>>>>>>> Hello Thorsten,
>>>>>>>>
>>>>>>>> What output comes with this command:
>>>>>>>>
>>>>>>>> Netdom TRUST trustingdomain /domain:TRUSTEDDOMAIN
>>>>>>>> /quarantine:no /usero:useraccount/passwordoassword
>>>>>>>>
>>>>>>>> Best regards
>>>>>>>>
>>>>>>>> Meinolf Weber
>>>>>>>> Disclaimer: This posting is provided "AS IS" with no
>>>>>>>> warranties,
>>>>>>>> and
>>>>>>>> confers no rights.
>>>>>>>> ** Please do NOT email, only reply to Newsgroups
>>>>>>>> ** HELP us help YOU!!!
>>>>>>>> http://www.blakjak.demon.co.uk/mul_crss.htm
>>>>>>>>> Hello,
>>>>>>>>>
>>>>>>>>> We are planning to do inter-forest users and group migration.
>>>>>>>>> Now we have a trust between the W2k and the W2k8 Domain. The
>>>>>>>>> SID Filter on the W2k Domain ist eneabled and if we use the
>>>>>>>>> comannd "Netdom TRUST <TrustingDomain> /domain:<TrustedDomain>
>>>>>>>>> /FilterSIDs:No /userD:<domainadminAcct>
>>>>>>>>> /passwordD:<domainadminpwd>", we got a "Access Denied". The
>>>>>>>>> user on both Domains are Domain- /Enterprise Admins. How can
>>>>>>>>> we disable the SID-filter between a W2k and a W2k8
>>>>>>>>> inter-forest trust?
>>>>>>>>>
>>>>>>>>> Thanks.
>>>>>>>>>
>>>>>>>>> Thorsten
>>>>>>>>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
filter out domain user accounts without email addresses inenewbl Active Directory 2 07-10-2009 05:36 PM
Filter mails comin from specific domain and directing it to a folder in Outlook Daniel Jewel Windows Small Business Server 11 01-30-2008 07:24 AM
help. Digital filter? how to de-filter? USB audio device Windows Vista Hardware 0 12-09-2006 09:30 PM
Difference of FS filter and mini-filter driver Dev Windows Vista Drivers 1 11-15-2006 12:20 PM
ISA 2000 Cannot load an application filter FTP Access Filter cptmidnight Windows Small Business Server 1 09-16-2005 11:00 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59