SKIP HACK metze ... out.sddl
authorStefan Metzmacher <metze@samba.org>
Fri, 22 Aug 2014 19:49:57 +0000 (21:49 +0200)
committerStefan Metzmacher <metze@samba.org>
Wed, 27 Aug 2014 10:53:49 +0000 (12:53 +0200)
commitdfbc12eb1c4a02706a0a3df480e431175dc875c5
tree7a22e8a46d1303a9cd2a4043b96f87ec1344829a
parentbb76c373067871746cba26d0fd7ee3bacd9caef0
SKIP HACK metze ... out.sddl

Note: the nTSecurityDescriptor on the *DnsZones partitions, doesn't match what
samba generates...

We should have the following:

ForestDnsZones = ObjectOwner:SY, ObjectGroup:BA, DomainControllers:ED

DomainDnsZones (toplevel) = ObjectOwner:SY, ObjectGroup:BA, DomainControllers:DD

DomainDnsZones (subdomain) = ObjectOwner:FirstDCAccount, ObjectGroup:SubdomainControllers, DomainControllers:SubdomainControllers

It's important to get this right before people start using subdomains,
as samba-tool dbcheck based fixes would be complex...
out.sddl [new file with mode: 0644]