Hi Obaid,
Thank you for the attached information. I think it answers the question. Will 
let you know if something else comes up, but at this point this seems 
reasonable.
 
Regards,
Nadezhda Ivanova
 
 
From: Obaid Farooqi [mailto:[email protected]] 

Sent: Friday, August 14, 2009 7:12 PM

 To: Nadezhda Ivanova

 Cc: [email protected]; [email protected]

 Subject: RE: Question about owner and group defaulting rules in MS-ADTS

 
Hi Nadezhda:
We have finished our investigation on "Owner and Group Defaulting Rules". In a 
future version of MS-ADTS, section 7.1.3.6 and 7.1.3 will be modified. Please 
find the PDF version of modifications attached to this email.
 
Please let me know if this answers your question. If yes, I'll consider this 
issue resolved.
 
Regards,
Obaid Farooqi
Sr. Support Escalation Engineer | Microsoft
 
 
From: Nadezhda Ivanova [mailto:[email protected]] 

Sent: Tuesday, August 04, 2009 2:58 AM

 To: Interoperability Documentation Help

 Cc: [email protected]; [email protected]

 Subject: Question about owner and group defaulting rules in MS-ADTS


 
Hi,
In MS-ADTS, section 7.1.3.6, is written the following:
 
The GROUP field is defaulted as follows: 
ยง If the DAG was used as the default OWNER field value, then the same SID is 
written into the GROUP field. 

However, it appears that the creating user's primary group is ALWAYS used as 
the default group, regardless of partition or owner. 
Example:
We create an object in the domain partition, say an OU, without providing an 
nTSecurityDescriptor. The creating user is a member of Domain Admins, with 
primary group Domain Users, so the DAG is Domain admins as per the DAG rules in 
the same document. Domain Admins is used as the OWNER in the new object's 
security descriptor. According to the above statement, Domain Admins should 
also be set as the default group. However, in a Windows 2003 server, Domain 
Users is defaulted as the group in the new object's descriptor. If the user's 
primary group is changed to Domain Admins, then the group of the new object is 
defaulted to Domain Admins.
 
The above behavior is consistent with CreateSecurityDescriptor algorithm from 
MS-DTYP, where the primary group of the security token is assigned if a group 
is not provided. 

Could you please clarify the contradiction between MS-ADTS, MS-DTYP and actual 
behavior?
 
Regards,
Nadezhda Ivanova
        
Nadezhda Ivanova

 Software EngineerSoftware Development

 [email protected]  CISCO SYSTEMS BULGARIA EOOD

 18 Macedonia Blvd. Sofia 1606

 Bulgaria

                
Think before you print.         
 


<<image001.gif>>

<<image002.gif>>

_______________________________________________
cifs-protocol mailing list
[email protected]
https://lists.samba.org/mailman/listinfo/cifs-protocol

Reply via email to