summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorGerald Carter <jerry@samba.org>2006-03-15 05:50:52 +0000
committerGerald (Jerry) Carter <jerry@samba.org>2007-10-10 11:15:30 -0500
commitb6170910604dba6533b727de8d7f0cc75256d14f (patch)
treea0ba3189ac2ecd2897d27fc35bddb42e3213527f
parenta39cbaa699d111264c2c9dda49a6e4f42acd3fb8 (diff)
downloadsamba-b6170910604dba6533b727de8d7f0cc75256d14f.tar.gz
samba-b6170910604dba6533b727de8d7f0cc75256d14f.tar.xz
samba-b6170910604dba6533b727de8d7f0cc75256d14f.zip
r14432: Give in and grant BUILT\Administrators all privileges
-rw-r--r--source/lib/account_pol.c7
-rw-r--r--source/lib/privileges.c20
2 files changed, 25 insertions, 2 deletions
diff --git a/source/lib/account_pol.c b/source/lib/account_pol.c
index 75a1d62ee79..0694b1c3f88 100644
--- a/source/lib/account_pol.c
+++ b/source/lib/account_pol.c
@@ -288,12 +288,17 @@ BOOL init_account_policy(void)
/* These exist by default on NT4 in [HKLM\SECURITY\Policy\Accounts] */
privilege_create_account( &global_sid_World );
- privilege_create_account( &global_sid_Builtin_Administrators );
privilege_create_account( &global_sid_Builtin_Account_Operators );
privilege_create_account( &global_sid_Builtin_Server_Operators );
privilege_create_account( &global_sid_Builtin_Print_Operators );
privilege_create_account( &global_sid_Builtin_Backup_Operators );
+ /* BUILTIN\Administrators get everything -- *always* */
+
+ if ( !grant_all_privileges( &global_sid_Builtin_Administrators ) ) {
+ DEBUG(0,("init_account_policy: Failed to grant privileges to BUILTIN\\Administrators!\n"));
+ }
+
return True;
}
diff --git a/source/lib/privileges.c b/source/lib/privileges.c
index ee69613df0e..d77d7857d72 100644
--- a/source/lib/privileges.c
+++ b/source/lib/privileges.c
@@ -867,9 +867,27 @@ BOOL privilege_set_to_se_priv( SE_PRIV *mask, PRIVILEGE_SET *privset )
/*******************************************************************
*******************************************************************/
-BOOL is_privileged_sid( DOM_SID *sid )
+BOOL is_privileged_sid( const DOM_SID *sid )
{
SE_PRIV mask;
return get_privileges( sid, &mask );
}
+
+/*******************************************************************
+*******************************************************************/
+
+BOOL grant_all_privileges( const DOM_SID *sid )
+{
+ int i;
+ SE_PRIV mask;
+ uint32 num_privs = count_all_privileges();
+
+ se_priv_copy( &mask, &se_priv_none );
+
+ for ( i=0; i<num_privs; i++ ) {
+ se_priv_add(&mask, &privs[i].se_priv);
+ }
+
+ return grant_privilege( sid, &mask );
+}