s4-drs: added new SECURITY_RO_DOMAIN_CONTROLLER level
authorAndrew Tridgell <tridge@samba.org>
Thu, 22 Apr 2010 06:48:01 +0000 (16:48 +1000)
committerAndrew Tridgell <tridge@samba.org>
Thu, 22 Apr 2010 09:36:16 +0000 (19:36 +1000)
commitbb1ba4ff76eb90d0d62dd3edbe288f45cf7a0a1e
tree8fd3704eb6819063b1916c78bb1893ba16c7fe72
parentec0bb2f46b855d44cccb71a5511c2acb7d8eae09
s4-drs: added new SECURITY_RO_DOMAIN_CONTROLLER level

This is used for allowing operations by RODCs, and denying them
operations that should only be allowed for a full DC

This required a new domain_sid argument to
security_session_user_level()

Pair-Programmed-With: Andrew Bartlett <abartlet@samba.org>
Pair-Programmed-With: Rusty Russell <rusty@samba.org>
13 files changed:
source4/dsdb/samdb/ldb_modules/kludge_acl.c
source4/dsdb/samdb/ldb_modules/repl_meta_data.c
source4/dsdb/samdb/ldb_modules/rootdse.c
source4/dsdb/samdb/ldb_modules/util.c
source4/libcli/security/security.h
source4/libcli/security/security_token.c
source4/rpc_server/drsuapi/addentry.c
source4/rpc_server/drsuapi/dcesrv_drsuapi.c
source4/rpc_server/drsuapi/dcesrv_drsuapi.h
source4/rpc_server/drsuapi/drsutil.c
source4/rpc_server/drsuapi/updaterefs.c
source4/rpc_server/lsa/dcesrv_lsa.c
source4/rpc_server/winreg/rpc_winreg.c