Leaked source code of windows server 2003
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

70 lines
3.9 KiB

  1. <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN" "http://www.w3.org/TR/REC-html40/strict.dtd">
  2. <HTML DIR="LTR">
  3. <HEAD>
  4. <TITLE>Compatibility Details</TITLE>
  5. <META HTTP-EQUIV="Content-Type" CONTENT="text-html;charset=Windows-1252">
  6. </HEAD>
  7. <BODY BGCOLOR="#ffffff">
  8. <FONT FACE="verdana" SIZE="2">
  9. <P>Before you can upgrade this Windows&nbsp;NT&nbsp;4.0 primary domain controller (PDC)
  10. you must disable security identifier (SID) filtering on external trusts</P>
  11. <P><B>Summary </B></P>
  12. <P>SID filtering is applied to one or more external trusts
  13. from this domain. Windows&nbsp;2000&nbsp;Server and Windows&nbsp;Server&nbsp;2003 Setup requires
  14. that you disable SID filtering for all trusts that are established from this
  15. Windows&nbsp;NT&nbsp;4.0 domain before you can upgrade.</P>
  16. <P><B>Description </B></P>
  17. <P>SID filtering increases the security of communications across domains or
  18. forests. Using SID filtering, an administrator can specify that the domain
  19. controllers in a given domain quarantine a trusted domain. This causes the
  20. domain controllers in a trusting domain to remove all SIDs that did not
  21. originate from the trusted domain, thereby preventing authorization data from
  22. passing to resources located in the trusting domain. For more information about
  23. SID filtering, see Q289246, &quot;Forged SID
  24. Could Result in Elevated Privileges in Windows&nbsp;NT&nbsp;4.0&quot; in the <A
  25. href="http://go.microsoft.com/fwlink/?LinkId=12659">Microsoft
  26. Knowledge Base</A>.</P>
  27. <P>After you have upgraded this Windows&nbsp;NT&nbsp;4.0 PDC, you should determine whether
  28. SID filtering will still be necessary after you install the upgrade. For more
  29. information about how to determine this, start Help and Support Center by
  30. clicking <B>Start</B>, clicking <B>Help and Support</B>, and then, in <B>Search</B>, type <B>Securing
  31. external trusts</B>. For more information about how to disable SID filtering, see Q811961, &quot;Windows&nbsp;2000&nbsp;Server and Windows&nbsp;Server&nbsp;2003 Setup Does Not Succeed When You Upgrade from a Windows&nbsp;NT&nbsp;4.0-Based Primary Domain Controller&quot; in the <A
  32. href="http://go.microsoft.com/fwlink/?LinkId=12546">Microsoft Knowledge Base</A>. </P>
  33. <P><B>Disabling SID filtering on external trusts </B></P>
  34. <P>To disable SID
  35. filtering, you need to modify a registry key on this Windows&nbsp;NT&nbsp;4.0 PDC.</P>
  36. <BLOCKQUOTE><B>Caution</B><BR>
  37. Incorrectly editing the registry may severely
  38. damage your system. Before making changes to the registry, you should back up
  39. any valued data on the computer. </BLOCKQUOTE>
  40. <OL>
  41. <LI>Click <B>Start</B>, and then click <B>Run</B>.</LI>
  42. <LI>Type <B>Regedt32.exe</B>, and then click <B>OK</B>.</LI>
  43. <LI>Locate the <B>REG_MULTI_SZ</B> value named <B>QuarantinedDomains</B> in the following
  44. registry key:
  45. <B>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters</B></LI>
  46. <LI>Backup the value of the following key, and then delete the key:
  47. <B>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters\QuarantinedDomains</B></LI>
  48. </OL>
  49. <P><B>Notes</B></P>
  50. <UL>
  51. <LI>This value must be removed before you can upgrade the Windows&nbsp;NT&nbsp;4.0 PDC.</LI>
  52. <LI>By removing the <B>QuarantinedDomains</B> registry key, you disable SID filtering
  53. for all external trusts.</LI>
  54. <LI>To achieve consistent results with other domain controllers in that
  55. domain, it is recommended that you remove the <B>QuarantinedDomains</B> registry key
  56. from all backup domain controllers (BDCs) in the upgraded domain.</LI>
  57. <LI>If you decide to apply SID filtering to external trusts from this domain
  58. in the future, you need to reinsert the <B>QuarantinedDomains</B> registry key on all
  59. Windows&nbsp;NT&nbsp;4.0 BDCs and add the NetBIOS domain name of each filtered domain to
  60. the key. </LI>
  61. </UL>
  62. </FONT>
  63. </BODY>
  64. </HTML>