svn commit: samba r6008 - in trunk/source/rpc_server: .

Gerald (Jerry) Carter jerry at samba.org
Wed Mar 23 22:35:38 GMT 2005


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simo Sorce wrote:

|>You can comment it out, but don't revert it - I don't want to
|>forget this.
|
| Ok, I already have some other fixes coming down the pipe,
| it's just that Jerry (on IRC) asked to NOT add privileges yet :-)

ok.  Simo caught me before I had read any commit messages.
I don't want to start adding new privileges willie-nillie
because it will get unmanageable before too long.

I would rather change the check to if (a) is root, or
(b) enable privileges = yes and is a member of domain admins.
Very similar to the check for creating domain trust accounts.

The SeDIskOperatorPrivilege should be reserved for managing
file share ACLs and smb.conf definitions.

Sounds like an acceptable solution ?






cheers, jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCQe86IR7qMdg1EfYRAoqZAKDgTUUxvumBKfoOiyqjXMByuF9bvQCfU2PA
lO/3LpNPYvZy/m5jxTSWj7g=
=84Mk
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list