s3:net rpc registry: make getsd succeed when key sd only gives access to SD not key...
authorMichael Adam <obnox@samba.org>
Mon, 21 Jun 2010 10:32:57 +0000 (12:32 +0200)
committerMichael Adam <obnox@samba.org>
Mon, 21 Jun 2010 10:38:25 +0000 (12:38 +0200)
You don't need the REG_KEY_READ permissions to access the SD of a key.
And for instance, the key HKLM\security ususally has no specific bits
set for builtin\administrators, but the READ_CONTROL_ACCESS.
I.e. builtin\administrators can get the sd but not enumerate the key.

source3/utils/net_rpc_registry.c

index 59971af3a359983116b7a27ffd67a8b14f880dc7..fb1e14f0d5cd754ebc0d1696ad3bedae3d6bfc42 100644 (file)
@@ -1208,8 +1208,7 @@ static NTSTATUS rpc_registry_getsd_internal(struct net_context *c,
        uint32_t sec_info;
        DATA_BLOB blob;
        struct security_descriptor sec_desc;
-       uint32_t access_mask = REG_KEY_READ |
-                              SEC_FLAG_MAXIMUM_ALLOWED |
+       uint32_t access_mask = SEC_FLAG_MAXIMUM_ALLOWED |
                               SEC_FLAG_SYSTEM_SECURITY;
 
        if (argc <1 || argc > 2 || c->display_usage) {