Article ID: 948502 - Last Review: October 24, 2008 - Revision: 1.0 Error message when you try to store a security descriptor by using an administration tool or a script in Windows Server 2003: "The security ID structure is invalid Facility: Win32 ID no: 80070539"On This PageSYMPTOMSOn a Windows Server 2003-based computer, you have an
administration tool or a script that uses the Active Directory Service
Interfaces (ADSI) IADs interface to manage security descriptors. You load a
security descriptor for editing by using the administration tool or the script.
When you try to store the
security descriptor, you may receive an error message that resembles the
following
error message: The security ID structure is invalid. Facility: Win32 ID no: 80070539 Note This problem may also occur in Windows Vista and Windows Server 2008. CAUSEThis problem may occur when the owner of
the objects is in a domain other than the domain where
the administration tool or the script is running. Also, the computer where the tool or script runs does not have the correct connectivity enabled with the domain where the owner account is defined. In this situation, you can run a code path where the security descriptor can be loaded. However, this code path fails for owner user and owner group even if these entries were not changed. WORKAROUNDTo work around this problem, use one of the following
methods. Method 1Open all required ports for the Local Security Authority (LSA) service according to Microsoft Knowledge Base article 832017.832017
(http://support.microsoft.com/kb/832017/
)
Service
overview and network port requirements for the Windows Server system
Method 2Block all ports to the domain controllers of other domains.Method 3Manage the security descriptor by using another computer that has firewall rules that allow this operation against the remote domain controller to succeed.Method 4Change the owner of the objects to a user or group in the domain where the administration tool or the script is running.STATUSMicrosoft
has confirmed that this is a problem in the Microsoft products that are listed
in the "Applies to" section. APPLIES TO
| Article Translations
|
Back to the top
