Unable to add Active Directory group to Console or Manager Security


This article applies to:

  • Trustwave MailMarshal (SEG) 8.X and below
  • Active Directory

Symptoms:

  • Attempting to add a group to the security permission on the Console Security or Manager Security tabs of MailMarshal Manager Properties or Server Properties
  • Used the browse button to add the group, and the group is in the same domain.
  • Error message: Failed to convert user: Unable to get Sid - The trust relationship between this workstation and the primary domain failed.

Causes:

The Console Security and Manager Security use the pre-Windows 2000 name to add the group to the security section.  If the Group name and pre-Windows 2000 name do not match, this error results. 

Resolution:

To correct the problem, edit the properties of the Active Directory group using AD management tools. 

  • In the General tab of group properties, update the Group name (pre-Windows 2000) and ensure this name exactly matches the name of the group.
  • The image below highlights the field to change. This entry must match the group name shown above the line.

 


Last Modified 3/1/2020.
https://support.trustwave.com/kb/KnowledgebaseArticle12941.aspx