Displaying 6 results from an estimated 6 matches for "ceertain".
Did you mean:
certain
2015 Oct 29
3
Local Administrators (group) and delegation in AD
On 2015-10-29 12:23, Rowland Penny wrote:
> On 29/10/15 09:47, Davor Vusir wrote:
>> On 2015-10-29 09:52, Rowland Penny wrote:
>>> On 29/10/15 08:34, Davor Vusir wrote:
>>>> Hi all!
>>>>
>>>> We have got many delegations in our AD. To add a certain
>>>> administrator group to the local Administrators group you can use
2015 Oct 29
2
Local Administrators (group) and delegation in AD
...n.
> And as Samba database is not splitted in small files, if you give that
> non-root user the ability to modify Samba database files, or just one file,
> this user can modify all objects contained in that DB file. So the
> granularity of that kind of fake-delegation is awfully bad and ceertainly
> not what you want.
>
> Another way would be to reinvent the wheel installing products to access
> Samba's LDAP and place ACL on the LDAP tree (no idea if Samba's LDAP tree
> can do that) to simulate Windows delegation.
>
> But as I said, I need a nap right now :)
&g...
2015 Oct 29
0
Local Administrators (group) and delegation in AD
...y the command you
run.
And as Samba database is not splitted in small files, if you give that
non-root user the ability to modify Samba database files, or just one file,
this user can modify all objects contained in that DB file. So the
granularity of that kind of fake-delegation is awfully bad and ceertainly
not what you want.
Another way would be to reinvent the wheel installing products to access
Samba's LDAP and place ACL on the LDAP tree (no idea if Samba's LDAP tree
can do that) to simulate Windows delegation.
But as I said, I need a nap right now :)
2015-10-29 14:10 GMT+01:00 Davor...
2015 Oct 30
2
Local Administrators (group) and delegation in AD
...ll files, if you give that
>>> non-root user the ability to modify Samba database files, or just
>>> one file,
>>> this user can modify all objects contained in that DB file. So the
>>> granularity of that kind of fake-delegation is awfully bad and
>>> ceertainly
>>> not what you want.
>>>
>>> Another way would be to reinvent the wheel installing products to
>>> access
>>> Samba's LDAP and place ACL on the LDAP tree (no idea if Samba's LDAP
>>> tree
>>> can do that) to simulate Windo...
2015 Oct 29
0
Local Administrators (group) and delegation in AD
...not splitted in small files, if you give that
>> non-root user the ability to modify Samba database files, or just one
>> file,
>> this user can modify all objects contained in that DB file. So the
>> granularity of that kind of fake-delegation is awfully bad and
>> ceertainly
>> not what you want.
>>
>> Another way would be to reinvent the wheel installing products to access
>> Samba's LDAP and place ACL on the LDAP tree (no idea if Samba's LDAP
>> tree
>> can do that) to simulate Windows delegation.
>>
>> But a...
2015 Nov 03
0
Local Administrators (group) and delegation in AD
...e that
>>>> non-root user the ability to modify Samba database files, or just
>>>> one file,
>>>> this user can modify all objects contained in that DB file. So the
>>>> granularity of that kind of fake-delegation is awfully bad and
>>>> ceertainly
>>>> not what you want.
>>>>
>>>> Another way would be to reinvent the wheel installing products to
>>>> access
>>>> Samba's LDAP and place ACL on the LDAP tree (no idea if Samba's
>>>> LDAP tree
>>>> ca...