|
More info on tokensz and maxtokensize
regkey and its problem, as described by Dean earlier http://support.microsoft.com/default.aspx?scid=kb;en-us;327825 Thank you and have a splendid day! Kind Regards, Freddy Hartono Windows Administrator (ADSM/NT Security) Spherion Technology Group, For Agilent Technologies E-mail: [EMAIL PROTECTED] From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dean Wells Firstly, the so-called well-known ~1000
limitation and the ~5000 limitation are entirely unrelated. Regarding token bloat; the more accurate
max. SIDs value is 1015. This is due to 9 well-known SIDs that are always
present and should, therefore, not be part of any calculation as to what we can
be administratively affected. In addition, tickets handed out by 2K3 DCs always
contain DL group SIDs regardless of domain mode and, as such, are always a
little bigger than a corresponding ticket issued by a 2000 DC in mixed mode
(this is done solely to avoid inconsistencies during transition of modes --
considered a bug by many, myself included). In contrast, we do attempt to compress
specific tokens by maintaining only the RID (not the whole SID) where
applicable. A MaxTokenSize registry value exists that simply governs the
upper limit. Increasing the value will likely cause performance concerns
and, more significantly, potential application failures due to timeouts (too
many SIDs to compare, call does not return and app. assumes failure).
This article eludes to the problem - Real-time token size can be calculated
using the following tool - -- From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Fischer Hi All: Can an AD user be a member of more that
1000 groups? Someone told me that 1000 was an AD limitation.
Is that true? Thanks, --Brian
| ||||||||||||||||
- RE: [ActiveDir] 1000 groups freddy_hartono
- RE: [ActiveDir] 1000 groups joe
- RE: [ActiveDir] 1000 groups joe
- RE: [ActiveDir] 1000 groups Dean Wells
- RE: [ActiveDir] 1000 groups Grillenmeier, Guido
- RE: [ActiveDir] 1000 groups Grillenmeier, Guido
- RE: [ActiveDir] 1000 groups joe
- RE: [ActiveDir] 1000 groups Dean Wells
- RE: [ActiveDir] 1000 groups Thommes, Michael M.
