Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

windows permissions

Thread Tools
 
Search this Thread
 
Old 16 December 2003, 12:36 PM
  #1  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

right then...

if fred exists in domain A & B with identical username & password..
fred needs resource from server1 in domain B, share is setup up with local group, local group has user from domain B in i...
it would appear that NTLM checks local machine for local user BUT NOT local group??

in other words I have to creat a local user on the resource server otherwise it prompts for user authentication....
I want it to appear seamless to users until single domain logon in 2 months time.

ps - if you understand this you are a geek

shunty
Old 16 December 2003, 12:38 PM
  #2  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

forgot to add:
resource server is windows 2003 server in windows 2000 ad domain.....access from an NT 4 domain

shunty
Old 16 December 2003, 12:46 PM
  #3  
shunty
Scooby Regular
Thread Starter
 
shunty's Avatar
 
Join Date: Aug 2001
Location: wakefield
Posts: 2,082
Likes: 0
Received 0 Likes on 0 Posts
Post

ahh, answered own question I think:

http://support.microsoft.com/?kbid=216970

so it's universal group needed in native mode.....
I thought I had done this before with no problems, this domain is in mixed mode.

"In a Native-mode domain, the Key Distribution Center (KDC) on the domain controller authenticating the user's logon request is responsible for adding the SIDs for global groups from the user's logon domain, locating and communicating with the GC to enumerate the universal groups the user is a member of, and adding the SIDs of those groups to the user's token. If the domain the computer resides in is in Native mode, any domain local groups from that domain of which the user is a member are added to the token. Lastly, any local groups from the local computer of which the user is a member are added to the token."

bu55er!!!

anyway round this rather than creating local users on servers then ??

shunty
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
hardcoreimpreza
Computer & Technology Related
21
11 October 2015 03:40 PM
FuZzBoM
Wheels, Tyres & Brakes
16
04 October 2015 09:49 PM
Ganz1983
Subaru
5
02 October 2015 09:22 AM



Quick Reply: windows permissions



All times are GMT +1. The time now is 04:37 AM.