[PATCH] Added "admin_session" method.

Nadezhda Ivanova nadezhda.ivanova at postpath.com
Mon Sep 7 07:22:46 MDT 2009


Hi Samba team,
As you know, I have been working on implementing AD compatible security descriptor inheritance in Samba 4. Based on documentation regarding the default owner and group of an SD and some experimentation, it appears that in order to get 100% compliance of the security descriptors in the schema, configuration and domain, provisioning has to be done by authenticating as Administrator. Maybe during plugfest we can establish if we need Administrator or any member of group Administrators. 

At this point basically we replace the system_session with admin_session when creating schema, configuration and domain partitions. It does not affect provisioning in any way and does not break any test.

Regards,
Nadya
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Added-admin_session-method.patch
Type: application/octet-stream
Size: 11910 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20090907/71897181/attachment.obj>


More information about the samba-technical mailing list