list of supported privileges in 3.0.11

Gerald (Jerry) Carter jerry at samba.org
Mon Jan 17 19:27:28 GMT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Andreas Hasenack wrote:
| On Mon, Jan 17, 2005 at 11:14:29AM -0600, Gerald (Jerry) Carter wrote:
|
|>-----BEGIN PGP SIGNED MESSAGE-----
|>Hash: SHA1
|>
|>This is what I have planned.  let me know if you have
|>any other suggestions.  Not all of them are done yet.
|>
|>* SeMachineAccountPrivilege - 	join client machines to the domain
|>* SePrintOperatorPrivilege  - 	print admin rights
|>* SeRemoteShutdownPrivilege - 	shutdown server (net rpc shutdown)
|>* SeServerOperatorPrivilege - 	add/modify/remove shares, modify
|>				share acls, etc...
|>* SeAddUsersPrivilege       -	add add/remove/modify users and
|>				groups
|>
|>I'm also going to include a new smb.conf option 'enable privileges'
|>which will default to 'no' since all Domain Admins will now posses
|>the right to modify the privileges associated with a SID.
|>
|>Other ideas?
|
|
| Could this help
| https://bugzilla.samba.org/show_bug.cgi?id=1773 somehow?

No.  different issue.  That's not actually our bug.
You need to check the ACL on the computer object in
AD and it ensures the necessary access for the acount you
use to join the domain.  Enable the advanced features
of the "AD User and Computers" MMC plugin.




cheers, jerry
=====================================================================
Alleviating the pain of Windows(tm)      ------- http://www.samba.org
GnuPG Key                ----- http://www.plainjoe.org/gpg_public.asc
"I never saved anything for the swim back."     Ethan Hawk in Gattaca
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFB7BGgIR7qMdg1EfYRAmJdAKCDwykdaamUBuzkEHhgdDdhLPXzKgCg2Bo4
l/A6Iv7aIvG6elr5Rp4tXbw=
=gEVs
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list