Lost Correct Security Identifier (SID): Event 5513

  • Thread starter Thread starter David
  • Start date Start date
D

David

I recently rebuilt our Domain controller with Active
Directory and DNS. During the installation I copied
netlogin.dns from the working computer to the new
server.From the new DC I am able to access all client
machines; however, the clients cant log in to the server.
All of the clients are able to route packets; however,
when anyone attempts to logon to the new DC, in the event
log, it states that the SID was lost. Microsoft says to
remove each machine from the domain, join a workgroup, and
then rejoin the domain(I have included this below). I am
unable to rejoin the domain on the new DC to recreate the
trust; however, I can join the old machine. How do I fix
this dilema??
Thanks in advance..

David
________________________________________________________
The computer computer name tried to connect to the server
computer name using the trust relationship established by
the name domain. However, the computer lost the correct
security identifier (SID) when the domain was
reconfigured. Reestablish the trust relationship.

Source Event Log Event ID Event Type
NetLogon System 5513 Error

Explanation:
When a Windows 2000 computer joins a domain, it obtains
the domain SID from the domain controller. The computer
retains the SID in its local security database.

User Action:
Remove and then add the computer to the domain again
 
Make the machines workgroup members first, then rejoin to the Domain. Also
make sure there is a functioning WINS Server (possibly on the new DC) and
that the clients have the new WINS and DNS server in their network settings
before you try to rejoin them. Also keep in mind that once you do, the user
will not be treated as the old users and they will have new "blank" profiles
because their accounts and profiles were also tied to the SID of the old
Domain which was lost. This implies that all the user accounts will have to
be recreated on the Domain since they would have been lost with the old one.

The proper way to handle this in the future is to always have at least two
DCs so that the old domain is never lost. When you rebuild one DC always
demote it first, make it a workgroup member, then rebuild, rejoin, then
re-promote to a DC. If you don't have two DCs then at least build a
temporary DC first then follow the steps I gave.

....or if anything,...have tape backups you can try to restore from. But
never just wipe the sole & only DC because that Domain is then gone forever
once you do.
 
Back
Top