Re: Setting ACLs from non-domain computer
Dominick Baier <[email protected]>
| Newsgroups | gmane.comp.windows.devel.dotnet.cx |
|---|---|
| Message-ID | <[email protected]> |
FileSystemRule takes an IdentityReference. This is either NTAccount or SecurityIdentifier. cheers, dominick ----------------------------- Dominick Baier, DevelopMentor http://www.leastprivilege.com -----Original Message----- From: Discussion relating to the specifics of the C# and Managed C++ languages [mailto:[email protected]] On Behalf Of Mont Rothstein Sent: Mittwoch, 6. September 2006 16:40 To: [email protected] Subject: Re: [DOTNET-CX] Setting ACLs from non-domain computer If I can get the SID for the group from the directory server (which I may be able to do) how can I use that to set the ACLs? FileSystemAccessRule() seems to only take the string name or a WindowsIdentity? I appreciate the assist, -Mont On 9/5/06, Dominick Baier <[email protected]> wrote: > > Hi, > > I don't think this will work - to set ACLs, the client must be able to > talk to the DC to resolve SIDs to Names and vice versa - this will > only work for domain members. > > Try this > > NTAccount acc = new NTAccount("domain\someAccOrGroup"); > SecurityIdentifier sid = > (SecurityIdentifier)acc.Translate(typeof(SecurityIdentitfier); > > this will most prolly not work (haven't verified it but I am quite sure). > > There is not WindowsIdentity for a group, you simply need the SID - > the above code is used by FileSecurity/DirectorySecurity under the covers. > > cheers, > dominick > > ----------------------------- > Dominick Baier, DevelopMentor > http://www.leastprivilege.com > > > -----Original Message----- > From: Discussion relating to the specifics of the C# and Managed C++ > languages [mailto:[email protected]] On Behalf Of Mont > Rothstein > Sent: Mittwoch, 6. September 2006 02:12 > To: [email protected] > Subject: [DOTNET-CX] Setting ACLs from non-domain computer > > I am using System.Security.AccessControl to set ACLs. > > I am also using LogonUser() to gain access to a share from a computer > that is not on the domain (using LOGON32_LOGON_NEW_CREDENTIALS). > > What I can't figure out is if there is anyway to set ACLs on > directories/files for groups from a non-domain computer. If I try and > simply pass in "domainname\groupname" to FileSystemAccessRule() I get > an exception when I go to modify the access rule (this works fine from > a computer on the domain). > > It seems it might work if I could get a WindowsIdentity for the group, > but I don't know how to do this or even if it can be done (is there > such a thing as a WindowsIdentity for a group?). > > Any help or pointers is appreciated. > > Thanks, > -Mont > > =================================== > This list is hosted by DevelopMentorR http://www.develop.com > > View archives and manage your subscription(s) at > http://discuss.develop.com > > =================================== > This list is hosted by DevelopMentor(r) http://www.develop.com > > View archives and manage your subscription(s) at > http://discuss.develop.com > =================================== This list is hosted by DevelopMentorR http://www.develop.com View archives and manage your subscription(s) at http://discuss.develop.com =================================== This list is hosted by DevelopMentor® http://www.develop.com View archives and manage your subscription(s) at http://discuss.develop.com