4 security IDL structures
10 const string SID_NULL = "S-1-0-0";
12 /* the world domain */
13 const string SID_WORLD_DOMAIN = "S-1-1";
14 const string SID_WORLD = "S-1-1-0";
16 /* SECURITY_CREATOR_SID_AUTHORITY */
17 const string SID_CREATOR_OWNER_DOMAIN = "S-1-3";
18 const string SID_CREATOR_OWNER = "S-1-3-0";
19 const string SID_CREATOR_GROUP = "S-1-3-1";
21 /* SECURITY_NT_AUTHORITY */
22 const string SID_NT_AUTHORITY = "S-1-5";
23 const string SID_NETWORK = "S-1-5-2";
24 const string SID_ANONYMOUS = "S-1-5-7";
25 const string SID_AUTHENTICATED_USERS = "S-1-5-11";
26 const string SID_SYSTEM = "S-1-5-18";
28 /* SECURITY_BUILTIN_DOMAIN_RID */
29 const string SID_BUILTIN = "S-1-5-32";
30 const string SID_BUILTIN_ADMINISTRATORS = "S-1-5-32-544";
31 const string SID_BUILTIN_USERS = "S-1-5-32-545";
32 const string SID_BUILTIN_GUESTS = "S-1-5-32-546";
33 const string SID_BUILTIN_POWER_USERS = "S-1-5-32-547";
34 const string SID_BUILTIN_ACCOUNT_OPERATORS = "S-1-5-32-548";
35 const string SID_BUILTIN_SERVER_OPERATORS = "S-1-5-32-549";
36 const string SID_BUILTIN_PRINT_OPERATORS = "S-1-5-32-550";
37 const string SID_BUILTIN_BACKUP_OPERATORS = "S-1-5-32-551";
38 const string SID_BUILTIN_REPLICATOR = "S-1-5-32-552";
40 /* a domain SID. Note that unlike Samba3 this contains a pointer,
41 so you can't copy them using assignment */
42 typedef [public,noprint] struct {
43 uint8 sid_rev_num; /**< SID revision number */
44 uint8 num_auths; /**< Number of sub-authorities */
45 uint8 id_auth[6]; /**< Identifier Authority */
46 uint32 sub_auths[num_auths];
49 typedef [public] struct {
50 uint8 type; /* xxxx_xxxx_ACE_TYPE - e.g allowed / denied etc */
51 uint8 flags; /* xxxx_INHERIT_xxxx - e.g OBJECT_INHERIT_ACE */
52 [value(ndr_size_security_ace(r))] uint16 size;
56 /* the 'obj' part is present when type is XXXX_TYPE_XXXX_OBJECT */
67 typedef [public] struct {
69 [value(ndr_size_security_acl(r))] uint16 size;
71 security_ace aces[num_aces];
74 /* default revision for new ACLs */
75 const int SD_REVISION = 1;
77 /* security_descriptor->type bits */
78 const int SEC_DESC_OWNER_DEFAULTED = 0x0001;
79 const int SEC_DESC_GROUP_DEFAULTED = 0x0002;
80 const int SEC_DESC_DACL_PRESENT = 0x0004;
81 const int SEC_DESC_DACL_DEFAULTED = 0x0008;
82 const int SEC_DESC_SACL_PRESENT = 0x0010;
83 const int SEC_DESC_SACL_DEFAULTED = 0x0020;
84 const int SEC_DESC_DACL_TRUSTED = 0x0040;
85 const int SEC_DESC_SERVER_SECURITY = 0x0080;
86 const int SEC_DESC_DACL_AUTO_INHERIT_REQ = 0x0100;
87 const int SEC_DESC_SACL_AUTO_INHERIT_REQ = 0x0200;
88 const int SEC_DESC_DACL_AUTO_INHERITED = 0x0400;
89 const int SEC_DESC_SACL_AUTO_INHERITED = 0x0800;
90 const int SEC_DESC_DACL_PROTECTED = 0x1000;
91 const int SEC_DESC_SACL_PROTECTED = 0x2000;
92 const int SEC_DESC_RM_CONTROL_VALID = 0x4000;
93 const int SEC_DESC_SELF_RELATIVE = 0x8000;
95 typedef [public,flag(NDR_LITTLE_ENDIAN)] struct {
97 uint16 type; /* SEC_DESC_xxxx flags */
98 [relative] dom_sid *owner_sid;
99 [relative] dom_sid *group_sid;
100 [relative] security_acl *sacl; /* system ACL */
101 [relative] security_acl *dacl; /* user (discretionary) ACL */
102 } security_descriptor;
104 typedef [public,printonly] struct {
107 } security_privilege;
109 typedef [public,printonly] struct {
115 dom_sid sids[num_sids];
116 uint32 num_restricted_sids;
117 dom_sid restricted_sids[num_restricted_sids];
118 uint32 num_privileges;
119 security_privilege privileges[num_privileges];