SEC_DESC_DACL_AUTO_INHERIT_REQ ?

Guenther Deschner gd at samba.org
Fri Oct 19 17:12:53 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Volker Lendecke wrote:
> Hi, Jeremy!
> 
> If I remember correctly, you at one point said that if
> SEC_DESC_DACL_AUTO_INHERIT_REQ is set during the
> set_security_descriptor call something magic happens with
> ACLs, namely that Windows copies the ACEs from the parent
> directories that are marked as inheritable are copied into
> the new security descriptor. I tried to reproduce this
> today, but I failed. Can you explain to me again what this
> actually does?

Hi Volker,

although not being Jeremy... Yes, this this bit is used to control
security descriptor inheritance e.g. on the winreg pipe. I have a
pending patch demonstrating this behaviour. Not sure how its supposed to
work on file ACLs though.

Guenther

- --
Günther Deschner                    GPG-ID: 8EE11688
Red Hat                         gdeschner at redhat.com
Samba Team                              gd at samba.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iD8DBQFHGOWVSOk3aI7hFogRAjEYAJ0c4BDri3C2gT2LADrMo49eRu+IIQCffYQu
i5+7wM+jbW8uGM0umNL3VUA=
=6QIP
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list