[cifs-protocol] LDAP_SERVER_SD_FLAGS_OID control and search request

Matthieu Patou mat+Informatique.Samba at matws.net
Fri Dec 18 09:35:55 MST 2009


Hello,

While testing ADUC I found that this tool is using the control 
LDAP_SERVER_SD_FLAGS_OID when requesting object with no attributes (ie. 
CN=Users,DC=home,DC=matws,DC=net) and expect to receive the 
nTSecurityDescriptor.
Of course if you do not provide this control the nTSecurityDescriptor is 
not returned.

I tested this behavior with w2k3r2 and it is how this server behave.

Can you confirm that it's the expected behavior for this control and if 
possible can you document it if it's not already done.

Regards.

Matthieu.


More information about the cifs-protocol mailing list