- Timestamp:
- Sep 24, 2009, 9:15:13 AM (16 years ago)
- File:
-
- 1 edited
Legend:
- Unmodified
- Added
- Removed
-
branches/samba-3.2.x/docs/htmldocs/Samba3-HOWTO/rights.html
r272 r335 2 2 <a class="indexterm" name="id2608159"></a> 3 3 <a class="indexterm" name="id2608166"></a> 4 <a class="indexterm" name="id260817 2"></a>5 <a class="indexterm" name="id26081 79"></a>4 <a class="indexterm" name="id2608173"></a> 5 <a class="indexterm" name="id2608180"></a> 6 6 The administration of Windows user, group, and machine accounts in the Samba 7 7 domain-controlled network necessitates interfacing between the MS Windows … … 25 25 <a class="indexterm" name="id2608252"></a> 26 26 <a class="indexterm" name="id2608259"></a> 27 <a class="indexterm" name="id260826 5"></a>27 <a class="indexterm" name="id2608266"></a> 28 28 Machine accounts are analogous to user accounts, and thus in implementing them on a UNIX machine that is 29 29 hosting Samba (i.e., on which Samba is running), it is necessary to create a special type of user account. … … 48 48 Windows secures authentication. 49 49 </p></div><p> 50 <a class="indexterm" name="id260836 1"></a>51 <a class="indexterm" name="id260836 8"></a>50 <a class="indexterm" name="id2608362"></a> 51 <a class="indexterm" name="id2608369"></a> 52 52 <a class="indexterm" name="id2608376"></a> 53 53 <a class="indexterm" name="id2608382"></a> … … 58 58 <code class="constant">root</code> account user. 59 59 </p><p> 60 <a class="indexterm" name="id260840 4"></a>60 <a class="indexterm" name="id2608405"></a> 61 61 <a class="indexterm" name="id2608412"></a> 62 <a class="indexterm" name="id260841 8"></a>63 <a class="indexterm" name="id260842 5"></a>62 <a class="indexterm" name="id2608419"></a> 63 <a class="indexterm" name="id2608426"></a> 64 64 All versions of Samba call system interface scripts that permit CIFS function 65 65 calls that are used to manage users, groups, and machine accounts … … 82 82 </p><p> 83 83 <a class="indexterm" name="id2608519"></a> 84 <a class="indexterm" name="id260852 5"></a>84 <a class="indexterm" name="id2608526"></a> 85 85 <a class="indexterm" name="id2608532"></a> 86 86 Currently, the rights supported in Samba-3 are listed in <a class="link" href="rights.html#rp-privs" title="Table 15.1. Current Privilege Capabilities">“Current Privilege Capabilities”</a>. 87 87 The remainder of this chapter explains how to manage and use these privileges on Samba servers. 88 </p><a class="indexterm" name="id2608550"></a><a class="indexterm" name="id2608556"></a><a class="indexterm" name="id260856 3"></a><a class="indexterm" name="id2608570"></a><a class="indexterm" name="id2608577"></a><a class="indexterm" name="id2608584"></a><div class="table"><a name="rp-privs"></a><p class="title"><b>Table 15.1. Current Privilege Capabilities</b></p><div class="table-contents"><table summary="Current Privilege Capabilities" border="1"><colgroup><col align="right"><col align="left"></colgroup><thead><tr><th align="left">Privilege</th><th align="left">Description</th></tr></thead><tbody><tr><td align="right"><p>SeMachineAccountPrivilege</p></td><td align="left"><p>Add machines to domain</p></td></tr><tr><td align="right"><p>SePrintOperatorPrivilege</p></td><td align="left"><p>Manage printers</p></td></tr><tr><td align="right"><p>SeAddUsersPrivilege</p></td><td align="left"><p>Add users and groups to the domain</p></td></tr><tr><td align="right"><p>SeRemoteShutdownPrivilege</p></td><td align="left"><p>Force shutdown from a remote system</p></td></tr><tr><td align="right"><p>SeDiskOperatorPrivilege</p></td><td align="left"><p>Manage disk share</p></td></tr><tr><td align="right"><p>SeTakeOwnershipPrivilege</p></td><td align="left"><p>Take ownership of files or other objects</p></td></tr></tbody></table></div></div><br class="table-break"><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2608726"></a>Using the “<span class="quote">net rpc rights</span>” Utility</h3></div></div></div><p>88 </p><a class="indexterm" name="id2608550"></a><a class="indexterm" name="id2608556"></a><a class="indexterm" name="id2608564"></a><a class="indexterm" name="id2608570"></a><a class="indexterm" name="id2608578"></a><a class="indexterm" name="id2608585"></a><div class="table"><a name="rp-privs"></a><p class="title"><b>Table 15.1. Current Privilege Capabilities</b></p><div class="table-contents"><table summary="Current Privilege Capabilities" border="1"><colgroup><col align="right"><col align="left"></colgroup><thead><tr><th align="left">Privilege</th><th align="left">Description</th></tr></thead><tbody><tr><td align="right"><p>SeMachineAccountPrivilege</p></td><td align="left"><p>Add machines to domain</p></td></tr><tr><td align="right"><p>SePrintOperatorPrivilege</p></td><td align="left"><p>Manage printers</p></td></tr><tr><td align="right"><p>SeAddUsersPrivilege</p></td><td align="left"><p>Add users and groups to the domain</p></td></tr><tr><td align="right"><p>SeRemoteShutdownPrivilege</p></td><td align="left"><p>Force shutdown from a remote system</p></td></tr><tr><td align="right"><p>SeDiskOperatorPrivilege</p></td><td align="left"><p>Manage disk share</p></td></tr><tr><td align="right"><p>SeTakeOwnershipPrivilege</p></td><td align="left"><p>Take ownership of files or other objects</p></td></tr></tbody></table></div></div><br class="table-break"><div class="sect2" lang="en"><div class="titlepage"><div><div><h3 class="title"><a name="id2608726"></a>Using the “<span class="quote">net rpc rights</span>” Utility</h3></div></div></div><p> 89 89 <a class="indexterm" name="id2608737"></a> 90 90 <a class="indexterm" name="id2608744"></a> … … 141 141 </p></dd></dl></div><div class="note" style="margin-left: 0.5in; margin-right: 0.5in;"><h3 class="title">Note</h3><p> 142 142 <a class="indexterm" name="id2608974"></a> 143 <a class="indexterm" name="id260898 0"></a>144 <a class="indexterm" name="id260898 7"></a>143 <a class="indexterm" name="id2608981"></a> 144 <a class="indexterm" name="id2608988"></a> 145 145 You must be connected as a member of the Domain Admins group to be able to grant or revoke privileges assigned 146 146 to an account. This capability is inherent to the Domain Admins group and is not configurable. There are no … … 159 159 </p><p> 160 160 <a class="indexterm" name="id2609048"></a> 161 <a class="indexterm" name="id260905 4"></a>161 <a class="indexterm" name="id2609055"></a> 162 162 <a class="indexterm" name="id2609061"></a> 163 163 Access as the root user (UID=0) bypasses all privilege checks. … … 165 165 <a class="indexterm" name="id2609080"></a> 166 166 <a class="indexterm" name="id2609086"></a> 167 <a class="indexterm" name="id260909 3"></a>167 <a class="indexterm" name="id2609094"></a> 168 168 The privileges that have been implemented in Samba-3.0.11 are shown below. It is possible, and likely, that 169 169 additional privileges may be implemented in later releases of Samba. It is also likely that any privileges … … 181 181 </p></dd><dt><span class="term">SeDiskOperatorPrivilege</span></dt><dd><p> 182 182 <a class="indexterm" name="id2609164"></a> 183 <a class="indexterm" name="id260917 1"></a>184 <a class="indexterm" name="id260917 8"></a>183 <a class="indexterm" name="id2609172"></a> 184 <a class="indexterm" name="id2609179"></a> 185 185 Accounts that possess this right will be able to execute 186 186 scripts defined by the <code class="literal">add/delete/change</code> … … 224 224 privileges: 225 225 <a class="indexterm" name="id2609392"></a> 226 <a class="indexterm" name="id2609 399"></a>226 <a class="indexterm" name="id2609400"></a> 227 227 <a class="indexterm" name="id2609407"></a> 228 228 <a class="indexterm" name="id2609414"></a> … … 237 237 <a class="indexterm" name="id2609477"></a> 238 238 <a class="indexterm" name="id2609484"></a> 239 <a class="indexterm" name="id260949 1"></a>240 <a class="indexterm" name="id260949 8"></a>241 <a class="indexterm" name="id260950 5"></a>239 <a class="indexterm" name="id2609492"></a> 240 <a class="indexterm" name="id2609499"></a> 241 <a class="indexterm" name="id2609506"></a> 242 242 <a class="indexterm" name="id2609512"></a> 243 243 <a class="indexterm" name="id2609519"></a> … … 245 245 <a class="indexterm" name="id2609533"></a> 246 246 <a class="indexterm" name="id2609540"></a> 247 <a class="indexterm" name="id260954 7"></a>247 <a class="indexterm" name="id2609548"></a> 248 248 </p><pre class="screen"> 249 249 SeCreateTokenPrivilege Create a token object … … 290 290 <a class="indexterm" name="id2609721"></a> 291 291 <a class="indexterm" name="id2609728"></a> 292 <a class="indexterm" name="id260973 4"></a>293 <a class="indexterm" name="id260974 1"></a>292 <a class="indexterm" name="id2609735"></a> 293 <a class="indexterm" name="id2609742"></a> 294 294 <a class="indexterm" name="id2609748"></a> 295 295 <a class="indexterm" name="id2609756"></a> … … 341 341 <a class="indexterm" name="id2609915"></a> 342 342 <a class="indexterm" name="id2609922"></a> 343 <a class="indexterm" name="id260992 8"></a>343 <a class="indexterm" name="id2609929"></a> 344 344 Please note that every Windows NT4 and later server requires a domain Administrator account. Samba versions 345 345 commencing with 3.0.11 permit Administrative duties to be performed via assigned rights and privileges … … 354 354 You may assign the domain administrator RID to an account using the <code class="literal">pdbedit</code> 355 355 command as shown here: 356 <a class="indexterm" name="id260997 6"></a>356 <a class="indexterm" name="id2609977"></a> 357 357 </p><pre class="screen"> 358 358 <code class="prompt">root# </code> pdbedit -U S-1-5-21-4294955119-3368514841-2087710299-500 -u root -r … … 394 394 group can be added to the membership of the local workstation group <code class="literal">Power Users</code>. 395 395 </p><p> 396 <a class="indexterm" name="id261019 3"></a>397 <a class="indexterm" name="id261020 0"></a>396 <a class="indexterm" name="id2610194"></a> 397 <a class="indexterm" name="id2610201"></a> 398 398 <a class="indexterm" name="id2610208"></a> 399 <a class="indexterm" name="id261021 4"></a>399 <a class="indexterm" name="id2610215"></a> 400 400 See <a class="link" href="NetCommand.html#nestedgrpmgmgt" title="Nested Group Support">Nested Group Support</a> for an example of how to add domain users 401 401 and groups to a local group that is on a Windows workstation. The use of the <code class="literal">net</code>
Note:
See TracChangeset
for help on using the changeset viewer.