VMware Cloud Community
Boug201110141
Contributor
Contributor

WS2008 R2 SP1 : Deployement of template, Customization (Sysprep), Same SID ??

Hello,

I have prepared a Windows Server 2008 R2 SP1 VM to be deployed as a template, I shutdown and converted it. The I deployed it and applied a Guest Customization. In the Customization Wizard i have selected "Generate New Security ID (SID)".

The deployement and the customization was successful : Customization of VM **** succeeded. Customization log located at C:\Windows\TEMP\vmware-imc\guestcust.log in the guest OS."


If I check the log, I see that a sysprerp has been executed with the good parameter (I think?) "Successfully executed command C:\windows\system32\sysprep\sysprep.exe /quiet /generalize /oobe /reboot /unattend:C:\sysprep\sysprep.xml"

Now when I check the SID with PsGetSid v1.44 : http://technet.microsoft.com/en-us/sysinternals/bb897417 , I have some strange result. Some VM have different SID and other share the same.

I don't understand why some of the VM have the same SID. Where can I find more log to troubleshoot this issue ? Have I made a mistake somewhere ?

Thanks for you help,

Reply
0 Kudos
1 Reply
Boug201110141
Contributor
Contributor

Hello,

A little update about my issue. In fact they never were issues. The sysprerp work perfectly. I analyse the SID of all the VM which were in an Active Directory domain, and only the DC and the secondary DC share the same SID :

DC                 S-1-5-21-XXXXXXXXXX-348XXXX150-31XXXX7983
DC                 S-1-5-21-XXXXXXXXXX-348XXXX150-31XXXX7983
DC                 S-1-5-21-XXXXXXXXXX-348XXXX150-31XXXX7983
DC                 S-1-5-21-XXXXXXXXXX-348XXXX150-31XXXX7983

WSUS           S-1-5-21-XXXXXXXXXX-215XXXX976-10XXXX2702
Test                S-1-5-21-XXXXXXXXXX-180XXXX848-91XXXX484
TEMPLATE   S-1-5-21-XXXXXXXXXX-285XXXX128-32XXXX963

It seems it is a perfectly normal behavior :

http://social.technet.microsoft.com/Forums/en-US/winserverDS/thread/21018090-fe12-40a2-801a-5f4406d1...

http://www.tech-archive.net/Archive/Windows/microsoft.public.windows.server.active_directory/2006-12...

DCs will share the same machine SID, but have different object SIDs assigned to them.

To get the object SIDs I used this command :

dsquery computer "CN=DC...." | dsget computer -sid

DC :                       S-1-5-21-XXXXXXXXXX-348XXXX150-31XXXX7983-1000

DC :                       S-1-5-21-XXXXXXXXXX-348XXXX150-31XXXX7983-2105

Reply
0 Kudos