#164714 - 2006-07-20 06:37 PM
Re: Ingroup seems not able to map drives
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
To answer that question we would need to know what version of KixTart 3.x or 4.x you are using. Please review this thread: http://www.kixtart.org/ubbthreads/showflat.php?Cat=&Board=UBB2&Number=62086
If you are using the 4.x KiXtart, then INGROUP processes the group memberships are attached to the user's security token by the AD global catalog server.
|
|
Top
|
|
|
|
#164716 - 2006-07-21 08:52 PM
Re: Ingroup seems not able to map drives
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
Have you verified that you have global Catalog server enabled, that they are working properly and that the clients can access them properly.
Are the Global Catalalog services properly registrered in DNS?
Ingroup (v4.02) works fine for me with my AD.
On an AD client, delete the following registry key: HKEY_CURRENT_USER\Software\KiXtart\TokenCache
Run the logon script is the key and its data recreated?
If yes, did the sids match the objects in the AD?
Are you using Sid history (Yuk!)?
Edited by Howard Bullock (2006-07-21 08:53 PM)
|
|
Top
|
|
|
|
#164719 - 2006-07-25 05:32 PM
Re: Ingroup seems not able to map drives
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
I suspect that something in your infrastructure is broken, but do not know exactly where to tell you to look other than the areas I mentioned above.
You state that only new clients are affected. Are you meaning only newly built computers in the AD domain? Or do older computers that have been migrated/moved to the AD domain also fail?
Have you reviewed the Token cache on an old and new computer? Is the new computers token cache populated?
Download KiXtart version 3.63 and run a test script that uses INGROUP. Does this version behave differently than your current version?
|
|
Top
|
|
|
|
#164721 - 2006-07-25 10:15 PM
Re: Ingroup seems not able to map drives
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
As documented in the links I have previously supplied, KiXtart 4.x checks the groups that are attached to the user's security token that is generated during the logon process.
You have not yet painted a complete infrastructure picture.
I now know that you have an old NT4 domain with some computers. And you have a new W2K domain with new computer as members.
You have not described how the user account are managed, migrated, or where they exist. Do the user's of the new computers in the new domain logon using accounts in the OLD NT4 domain or in the W2K domain?
From where does your logon execute for the computer in the new domain?
|
|
Top
|
|
|
|
#164722 - 2006-07-25 10:17 PM
Re: Ingroup seems not able to map drives
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
If your users are logging on to the new domain. You will need to rewrite your script for the new domain and the current groups that have been defined in the new domain.
|
|
Top
|
|
|
|
#164725 - 2006-08-15 09:51 PM
Re: Ingroup seems not able to map drives
|
Howard Bullock
KiX Supporter
   
Registered: 2000-09-15
Posts: 5809
Loc: Harrisburg, PA USA
|
Domain A (NT4)? All User accounts are in Domain A
Domain B (Windows 2000)? Computer Account live in Domain B
Domain B trusts Domain A (required) A one way trust is all that is required.
User on computer in Domain B logs on using DomainA\user1. Is this correct?
If the above is how your domain is constructed, then the links above that discuss how the global groups from Domain A are attached to the user's security token at Logon.
so... if INGROUP(DomainA\Global1) should work
Are your groups in Domain A local or global groups?
Let me know if the above description is accurate and if the example does or does not work.
Please post the contents of HKEY_CURRENT_USER\Software\KiXtart\TokenCache from a computer in Domain B.
|
|
Top
|
|
|
|
Moderator: Jochen, Allen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Arend_, Mart
|
0 registered
and 1376 anonymous users online.
|
|
|