Re: [cifs-protocol] Group Policy questions

2009-10-19 Thread Hongwei Sun
Matthieu, For Problem #1, only the SE_DACL_PROTECTED(0x1000) has to be set for ControlFlag in Security Descriptor in order to pass the step 2 in consistency testing. This is translated to P flag in SDDL. With this said, it is normal to have D:PAI since this will indicate that the

[cifs-protocol] Explain not standard behaviour of Windows 2003 server

2009-10-19 Thread Matthieu Patou
Hello, In MS-NRPC for response to GetDomainInfo the DC usually return a NETLOGON_DOMAIN_INFO structure. This stucture as explained in 2.2.1.3.11 contains a field called SupportedEncTypes. This field is definied like this: SupportedEncTypes: A set of bit flags that specify the encryption

Re: [cifs-protocol] Explain not standard behaviour of Windows 2003 server

2009-10-19 Thread Matthieu Patou
Hi Obaid, The frames are encrypted (schannel encryption). Do you have the opportunity to rebuild a wireshark if so using my patchs you can quite easily decrypt them of not then it's gonna be more difficult ... Matthieu. On 08/10/2009 08:47 PM, Obaid Farooqi wrote: Hi Matthieu: Please send

Re: [cifs-protocol] Explain not standard behaviour of Windows 2003 server

2009-10-19 Thread Matthieu Patou
Hi Obaid, Now it's more clear concerning the SupportedEncTypes but as I reread the MS-NRPC.pdf doc I still didn't find obvious that the SupportedEncTypes is in fact the list of client's supported encoding as it is currently known by the server. At first I thought it was the list of