Sid translation across domains

G

Guest

Hi,
I have two domains set up (both 2003 server) with a two way trust
relationship.
everything is working fine except for the following -
I can add a user from domain A into domain B and give them access to
resources no problem, however, if i close the group properties dialogue box
and reopen it the user-friendly name is not resolved, i can only see the SID.
The error message is - "Some of the objects names cannot be shown in their
user-friendly form. This can only happen if the object is from an external
domain and that domain is not available to translate the object's name".
the users still get access to the resource and when i go to add a new user
to the group it shows all the users in domain A and i can select them by
name? but once i close it then reopen it the same error appears.

I have tried enabling the allow anonymous SID and have also set the LSA to
zero.
name resolution works okay and there is an entry in the hosts file of each
DC for each other.
any suggestions of where to look from here?
 
G

Guest

Thanks for the info Mitch.
I have tried this and the command completed successfully on both domains
however i still have the same problem? both DC's have been rebooted.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top