OneFS - How To View Active Directory Provider Status and User Mapping Token Information - Dell India
OneFS - How To View Active Directory Provider Status and User Mapping Token Information - Dell India
Article Content
Instructions
Introduction
When troubleshooting authentication issues or issues related to user and group permissions, you can view the status of the Active
Directory (AD) provider and the user mapping token information.
Procedure
OneFS 7.0 and later versions
1. Open an SSH connection on any node in the cluster and log on using the "root" account.
2. Run the following command, where <domain> is the domain name and <user name> is the user name of the user you want to
look up:
Name: CORP\administrator
DN: CN=Administrator,CN=Users,DC=corp,DC=domain,DC=com
DNS Domain: corp.domain.com
Domain: CORP
Provider: lsa-activedirectory-provider:CORP.DOMAIN.COM
Sam Account Name: Administrator
UID: 1000002
SID: S-1-5-21-458040702-84545701-2247583341-500
Enabled: Yes
Expired: No
Expiry: -
Locked: No
Email: -
GECOS: -
Generated GID: Yes
Generated UID: Yes
Generated UPN: Yes
Primary Group
ID: GID:1000000
Name: CORP\domain users
Home Directory: /ifs/home/CORP/administrator
Max Password Age: -
Password Expired: No
Password Expiry: -
Password Last Set: 2014-11-04T07:59:42
Password Expires: No
https://www.dell.com/support/kbdoc/en-in/article/lkbprint?ArticleNumber=000008331&AccessLevel=10&Lang=en 1/5
8/18/22, 4:28 PM OneFS: How to view Active Directory provider status and User Mapping Token Information | Dell India
Shell: /bin/zsh
UPN: [email protected]
User Can Change Password: Yes
Additional Groups: CORP\group policy creator owners
CORP\schema admins
CORP\enterprise admins
CORP\denied rodc password replication group
CORP\domain admins
CORP\domain users
3. To get a list of the AD providers and their statuses, run the following command:
Name: CORP.DOMAIN.COM
Status: online
Primary Domain: CORP.DOMAIN.COM
Forest: corp.domain.com
Site: Default-First-Site-Name
NetBIOS Domain: CORP
Hostname: newt.corp.domain.com
Controller Time: 2015-05-27T19:05:15
Machine Account: NEWT$
5. To view the mapping token for the user which includes groups from all auth providers, run the following command:
User
Name: CORP\administrator
UID: 1000002
SID: S-1-5-21-458040702-84545701-2247583341-500
On Disk: S-1-5-21-458040702-84545701-2247583341-500
ZID: 1
Zone: System
Privileges: -
Primary Group
Name: CORP\domain users
GID: 1000000
SID: S-1-5-21-458040702-84545701-2247583341-513
On Disk: S-1-5-21-458040702-84545701-2247583341-513
Supplemental Identities
Name: CORP\group policy creator owners
GID: 1000015
SID: S-1-5-21-458040702-84545701-2247583341-520
https://www.dell.com/support/kbdoc/en-in/article/lkbprint?ArticleNumber=000008331&AccessLevel=10&Lang=en 2/5
8/18/22, 4:28 PM OneFS: How to view Active Directory provider status and User Mapping Token Information | Dell India
1. Open an SSH connection on any node in the cluster and log on using the "root" account.
2. Run the following command, where <domain> is the domain name and <user name> is the user name of the user you want to
look up:
User: CORP\administrator*
Uid: 1000001
Gid: 1000004(CORP\domain users)
Sid: S-1-5-21-458040702-84545701-2247583341-500
Shell: /bin/sh
Home: /ifs/home/CORP/administrator
Groups: 1000004(CORP\domain users), 1000000(CORP\denied rodc password replication group),
1000003(CORP\domain admins), 1000004(CORP\domain users), 1544(Administrators), 1545(Users),
1000005(CORP\group policy creator owners), 1000006(CORP\schema admins), 1000007(CORP\enterprise
admins)
Flags: Password Never Expires
3. To look up the status of the AD provider, run the following command:
To view the mapping token for the user which includes groups from all auth providers, run the following command:
https://www.dell.com/support/kbdoc/en-in/article/lkbprint?ArticleNumber=000008331&AccessLevel=10&Lang=en 3/5
8/18/22, 4:28 PM OneFS: How to view Active Directory provider status and User Mapping Token Information | Dell India
Final Token
---------------------------------------------------------------------------------------
Primary uid: CORP\administrator (1000001)
Primary user sid: CORP\administrator (SID:S-1-5-21-458040702-84545701-2247583341-500)
Primary gid: CORP\domain users (1000004)
Primary group sid: SID:S-1-5-21-458040702-84545701-2247583341-513
On-disk user identity: CORP\administrator (SID:S-1-5-21-458040702-84545701-2247583341-500)
On-disk group identity: CORP\domain users (SID:S-1-5-21-458040702-84545701-2247583341-513)
Additional Identities:
CORP\denied rodc password replication group (SID:S-1-5-21-458040702-84545701-2247583341-572)
CORP\denied rodc password replication group (GID:1000000)
CORP\domain admins (SID:S-1-5-21-458040702-84545701-2247583341-512)
CORP\domain admins (GID:1000003)
Administrators (SID:S-1-5-32-544)
Administrators (GID:1544)
Users (SID:S-1-5-32-545)
Users (GID:1545)
CORP\schema admins (SID:S-1-5-21-458040702-84545701-2247583341-518)
CORP\schema admins (GID:1000006)
CORP\group policy creator owners (SID:S-1-5-21-458040702-84545701-2247583341-520)
CORP\group policy creator owners (GID:1000005)
CORP\enterprise admins (SID:S-1-5-21-458040702-84545701-2247583341-519)
CORP\enterprise admins (GID:1000007)
Additional Information
Related articles:
Article Properties
Affected Product
Isilon
Product
Isilon, PowerScale OneFS
Version
5
https://www.dell.com/support/kbdoc/en-in/article/lkbprint?ArticleNumber=000008331&AccessLevel=10&Lang=en 4/5
8/18/22, 4:28 PM OneFS: How to view Active Directory provider status and User Mapping Token Information | Dell India
Article Type
How To
https://www.dell.com/support/kbdoc/en-in/article/lkbprint?ArticleNumber=000008331&AccessLevel=10&Lang=en 5/5