s4:provision_users.ldif - Remove system objects from the wrong place
[ira/wip.git] / source4 / setup / provision_users.ldif
index bc5616ba5b671c031782d6ca1182e8d04e5d52e8..2261b3b4a77e2feb13b8c545c5e9e7760e4e3c87 100644 (file)
@@ -1,5 +1,6 @@
-# Add default primary groups (domain users, domain guests) - needed for
-# the users to find valid primary groups (samldb module)
+# Add default primary groups (domain users, domain guests, domain computers &
+# domain controllers) - needed for the users to find valid primary groups
+# (samldb module)
 
 dn: CN=Domain Users,CN=Users,${DOMAINDN}
 objectClass: top
@@ -17,6 +18,23 @@ objectSid: ${DOMAINSID}-514
 sAMAccountName: Domain Guests
 isCriticalSystemObject: TRUE
 
+dn: CN=Domain Computers,CN=Users,${DOMAINDN}
+objectClass: top
+objectClass: group
+description: All workstations and servers joined to the domain
+objectSid: ${DOMAINSID}-515
+sAMAccountName: Domain Computers
+isCriticalSystemObject: TRUE
+
+dn: CN=Domain Controllers,CN=Users,${DOMAINDN}
+objectClass: top
+objectClass: group
+description: All domain controllers in the domain
+objectSid: ${DOMAINSID}-516
+adminCount: 1
+sAMAccountName: Domain Controllers
+isCriticalSystemObject: TRUE
+
 # Add users
 
 dn: CN=Administrator,CN=Users,${DOMAINDN}
@@ -67,23 +85,6 @@ adminCount: 1
 sAMAccountName: Enterprise Admins
 isCriticalSystemObject: TRUE
 
-dn: CN=Domain Computers,CN=Users,${DOMAINDN}
-objectClass: top
-objectClass: group
-description: All workstations and servers joined to the domain
-objectSid: ${DOMAINSID}-515
-sAMAccountName: Domain Computers
-isCriticalSystemObject: TRUE
-
-dn: CN=Domain Controllers,CN=Users,${DOMAINDN}
-objectClass: top
-objectClass: group
-description: All domain controllers in the domain
-objectSid: ${DOMAINSID}-516
-adminCount: 1
-sAMAccountName: Domain Controllers
-isCriticalSystemObject: TRUE
-
 dn: CN=Schema Admins,CN=Users,${DOMAINDN}
 objectClass: top
 objectClass: group
@@ -134,7 +135,7 @@ isCriticalSystemObject: TRUE
 dn: CN=Read-Only Domain Controllers,CN=Users,${DOMAINDN}
 objectClass: top
 objectClass: group
-description: read-only domain controllers
+description: Read-only domain controllers
 objectSid: ${DOMAINSID}-521
 sAMAccountName: Read-Only Domain Controllers
 groupType: -2147483644
@@ -143,39 +144,12 @@ isCriticalSystemObject: TRUE
 dn: CN=Enterprise Read-Only Domain Controllers,CN=Users,${DOMAINDN}
 objectClass: top
 objectClass: group
-description: enterprise read-only domain controllers
+description: Enterprise read-only domain controllers
 objectSid: ${DOMAINSID}-498
 sAMAccountName: Enterprise Read-Only Domain Controllers
 groupType: -2147483644
 isCriticalSystemObject: TRUE
 
-dn: CN=Certificate Service DCOM Access,CN=Users,${DOMAINDN}
-objectClass: top
-objectClass: group
-description: Certificate Service DCOM Access
-objectSid: ${DOMAINSID}-574
-sAMAccountName: Certificate Service DCOM Access
-groupType: -2147483644
-isCriticalSystemObject: TRUE
-
-dn: CN=Cryptographic Operators,CN=Users,${DOMAINDN}
-objectClass: top
-objectClass: group
-description: Cryptographic Operators
-objectSid: ${DOMAINSID}-569
-sAMAccountName: Cryptographic Operators
-groupType: -2147483644
-isCriticalSystemObject: TRUE
-
-dn: CN=Event Log Readers,CN=Users,${DOMAINDN}
-objectClass: top
-objectClass: group
-description: Event Log Readers
-objectSid: ${DOMAINSID}-573
-sAMAccountName: Event Log Readers
-groupType: -2147483644
-isCriticalSystemObject: TRUE
-
 # Add foreign security principals
 
 dn: CN=S-1-5-4,CN=ForeignSecurityPrincipals,${DOMAINDN}
@@ -212,30 +186,6 @@ adminCount: 1
 sAMAccountName: Administrators
 systemFlags: -1946157056
 groupType: -2147483643
-privilege: SeSecurityPrivilege
-privilege: SeBackupPrivilege
-privilege: SeRestorePrivilege
-privilege: SeSystemtimePrivilege
-privilege: SeShutdownPrivilege
-privilege: SeRemoteShutdownPrivilege
-privilege: SeTakeOwnershipPrivilege
-privilege: SeDebugPrivilege
-privilege: SeSystemEnvironmentPrivilege
-privilege: SeSystemProfilePrivilege
-privilege: SeProfileSingleProcessPrivilege
-privilege: SeIncreaseBasePriorityPrivilege
-privilege: SeLoadDriverPrivilege
-privilege: SeCreatePagefilePrivilege
-privilege: SeIncreaseQuotaPrivilege
-privilege: SeChangeNotifyPrivilege
-privilege: SeUndockPrivilege
-privilege: SeManageVolumePrivilege
-privilege: SeImpersonatePrivilege
-privilege: SeCreateGlobalPrivilege
-privilege: SeEnableDelegationPrivilege
-privilege: SeInteractiveLogonRight
-privilege: SeNetworkLogonRight
-privilege: SeRemoteInteractiveLogonRight
 isCriticalSystemObject: TRUE
 
 dn: CN=Users,CN=Builtin,${DOMAINDN}
@@ -272,9 +222,6 @@ adminCount: 1
 sAMAccountName: Print Operators
 systemFlags: -1946157056
 groupType: -2147483643
-privilege: SeLoadDriverPrivilege
-privilege: SeShutdownPrivilege
-privilege: SeInteractiveLogonRight
 isCriticalSystemObject: TRUE
 
 dn: CN=Backup Operators,CN=Builtin,${DOMAINDN}
@@ -286,10 +233,6 @@ adminCount: 1
 sAMAccountName: Backup Operators
 systemFlags: -1946157056
 groupType: -2147483643
-privilege: SeBackupPrivilege
-privilege: SeRestorePrivilege
-privilege: SeShutdownPrivilege
-privilege: SeInteractiveLogonRight
 isCriticalSystemObject: TRUE
 
 dn: CN=Replicator,CN=Builtin,${DOMAINDN}
@@ -353,12 +296,6 @@ adminCount: 1
 sAMAccountName: Server Operators
 systemFlags: -1946157056
 groupType: -2147483643
-privilege: SeBackupPrivilege
-privilege: SeSystemtimePrivilege
-privilege: SeRemoteShutdownPrivilege
-privilege: SeRestorePrivilege
-privilege: SeShutdownPrivilege
-privilege: SeInteractiveLogonRight
 isCriticalSystemObject: TRUE
 
 dn: CN=Account Operators,CN=Builtin,${DOMAINDN}
@@ -370,7 +307,6 @@ adminCount: 1
 sAMAccountName: Account Operators
 systemFlags: -1946157056
 groupType: -2147483643
-privilege: SeInteractiveLogonRight
 isCriticalSystemObject: TRUE
 
 dn: CN=Pre-Windows 2000 Compatible Access,CN=Builtin,${DOMAINDN}
@@ -382,8 +318,6 @@ objectSid: S-1-5-32-554
 sAMAccountName: Pre-Windows 2000 Compatible Access
 systemFlags: -1946157056
 groupType: -2147483643
-privilege: SeRemoteInteractiveLogonRight
-privilege: SeChangeNotifyPrivilege
 isCriticalSystemObject: TRUE
 
 dn: CN=Incoming Forest Trust Builders,CN=Builtin,${DOMAINDN}