Marcel
Wed Apr 23 04:20:00 PDT 2008
Ace,
Thanks for the swift response, however this doesn't answer my question. Let
me explain...
The Domain SID, taken from the technet-article you referred to is:
â?¢ A domain identifier (21-1004336348-1177238915-682003330), Contoso
What I would like to know is how the three (30bit) numbers are generated
when the Domain is created ? Is there a particular algorithm based on
hardware, date, time ?? Why are they seperated with dashes, are there three
separate algorithms ?
info appreciated
regards,
Marcel
"Ace Fekay [MVP]" wrote:
> In news:8611845E-831A-45D1-A1A9-CEE6A9F2046C@microsoft.com,
> Marcel <Marcel@discussions.microsoft.com> typed:
> > Anyone have any info on this question.
> > The Domainpart of a SID is largely based on three 30bit numbers that
> > are based on ... what ?
> >
> > info is much appreciated!
> >
> > grt
> > Marcel
>
>
> Basically it's derived from the combination of the domain SID and the RID #
> obtained from the RID pool for that type of object that is being created, to
> create the SID. This is one reason why the RID Master role is important.
>
> How Security Identifiers Work:
> For domain accounts, the SID of a security principal is created by
> concatenating the SID of the domain with a relative identifier (RID) for the
> account. ...
>
http://technet2.microsoft.com/WindowsServer/en/Library/5dbc99be-7404-41a6-9be7-171d40c398db1033.mspx
>
>
> --
> Regards,
> Ace
>
> This posting is provided "AS-IS" with no warranties or guarantees and
> confers no rights.
>
> Ace Fekay, MCSE 2003 & 2000, MCSA 2003 & 2000, MCSE+I, MCT,
> MVP Microsoft MVP - Directory Services
> Microsoft Certified Trainer
>
> For urgent issues, you may want to contact Microsoft PSS directly. Please
> check
http://support.microsoft.com for regional support phone numbers.
>
> Infinite Diversities in Infinite Combinations
>
>
>
>