Domain Admins as a GID only and classicupgrade

Andrew Bartlett abartlet at samba.org
Wed Aug 29 02:38:36 MDT 2012


On Wed, 2012-08-29 at 03:30 -0500, Ricky Nance wrote:
> Can the ACL code be dropped from classicupgrade until this is sorted, or
> does that pose some sort of risk (security or stability wise)?

The problem is that this exact ACL set is the same thing that needs to
happen if a new GPO is created, and is the fix to the 'only
administrator can set GPOs' issue.  The workaround of using the NTVFS
file server remains.

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org



More information about the samba-technical mailing list