Computer Account SID hell with virtual machines guests and gsgetsid.exe and NewSid.exe howto

14 12 2007

Today I configured new VMWare team and installed one domain controller and one other server as file server. I used my masterbuild server image of Win2k3 EE R2 and both images run the sysprep.exe routine. After the dc was setup to run AD and DNS I joined the second guest machine on the domain. The domain join on the second machine worked fine.

I reboot and tried to logon with a domain account and than with the domain admin. Both accounts generated the Logon Message below.

The system cannot log you on due the following error:

The name or security ID (SID) of the domain specified is inconsistent with the trust information for that domain.

Please try again or consult your system administrator.

clip_image001

I logged on with the local administrator account and saw the event id 5516 Netlogon error as shown below.

clip_image002

For some reason the sysprep did not work from my masterbuild and both virtual guest machines have the same SID id.

To verify both sid’s you can go and download the psgetsid.exe from Microsoft website.

http://www.microsoft.com/technet/sysinternals/utilities/psgetsid.mspx

I downloaded the pstools.zip from Microsoft website and run psgetsid.exe \\fs-001-cert and psgetsid.exe \\dc-001-cert. As shown below both match.

clip_image003

To quickly resolve this issue is to run the NewSid.exe tool and generate new SID for this computer account.

This tool is available at: http://www.microsoft.com/technet/sysinternals/Utilities/NewSid.mspx

Run the tool and generate new sid for you guest machine.

clip_image004

Next

clip_image005

Next

clip_image006

Click Next and reboot the machine.

Logon on the system with the local administrator account and join to the workgroup. Reboot the guest and rejoin to the domain.

If these steps are not executed than domain membership connectivity will fail!

clip_image007

After the reboot I was successfully being able to logon as my test user “Finance Manager”.


Actions

Informations

One response to “Computer Account SID hell with virtual machines guests and gsgetsid.exe and NewSid.exe howto”

14 08 2008
The things that are better left unspoken : Active Directory in Hyper-V environments, Part 2 (18:43:35) :

[...] Considerations when hosting Active Directory domain controller in virtual environments  Computer Account SID hell with virtual machines guests and gsgetsid.exe and NewSid.exe NewSID v4.10 by Mark Russinovich and Bryce Cogswell  [PPT] WIN388 Using Virtual PC 2004: Tips [...]

Leave a comment

You can use these tags : <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>