Re: [cifs-protocol] [REG113100710843173]: Question about LDAP delete operation on Administrator and other built-in accounts

2013-10-09 Thread Nadezhda Ivanova
:* Monday, October 07, 2013 11:37 AM *To:* Nadezhda Ivanova *Cc:* cifs-proto...@samba.org; MSSolve Case Email *Subject:* RE: [REG113100710843173]: Question about LDAP delete operation on Administrator and other built-in accounts ** ** Nadia, ** ** I will investigate this and follow

[cifs-protocol] Question about LDAP delete operation on Administrator and other built-in accounts

2013-10-07 Thread Nadezhda Ivanova
relevant to the case? Best Regards, Nadezhda Ivanova ___ cifs-protocol mailing list cifs-protocol@cifs.org https://lists.samba.org/mailman/listinfo/cifs-protocol

[cifs-protocol] Question about MS-DTYP 2.5.3.4 Algorithm for Creating a Security Descriptor

2011-02-09 Thread Nadezhda Ivanova
Hi, I have a question regarding 2.5.3.4 Algorithm for Creating a Security Descriptor. It is said there that any ACEs provided by the user that contain the INHERITED_ACE flag are not included in the final SD assigned to the object, and in the algorithm they are also disregarded. This is indeed

[cifs-protocol] Questions about Validated-SPN validated write

2010-12-17 Thread Nadezhda Ivanova
then the syntax restrictions described in MS-DRSR and MS-ADTS? If an object does not have Validated-SPN on Principal-Self, should the account still be allowed to set the above values via DRS? Best Regards, Nadezhda Ivanova ___ cifs-protocol mailing list cifs

Re: [cifs-protocol] [REG:110041557300829] RE: Questions regarding 7.1.3.1 ACE Ordering Rules

2010-04-19 Thread Nadezhda Ivanova
is in an OU where inheritance is broken, that is, it will not inherit anything from the parent. The sid variable is the sid of a regular user, I suppose any user would do. Thanks, Nadya - Original Message - From: Hongwei Sun hongw...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan

[cifs-protocol] Questions regarding 7.1.3.1 ACE Ordering Rules

2010-04-15 Thread Nadezhda Ivanova
Hello, I was running some test against a Windows 2008 server, forest functional level and domain functional level are both 2008. I created a group via LDAP and provided a security descriptor with ACE's deliberately scrambled - e.g Deny before Allow, Object Specific before Regular. I did not

Re: [cifs-protocol] [REG:110040646791367] : RE: Numerical value of FLAG_ATTR_REQ_PARTIAL_SET_MEMBER

2010-04-07 Thread Nadezhda Ivanova
: Hongwei Sun hongw...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan...@postpath.com, Interoperability Documentation Help doch...@winse.microsoft.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Tuesday, April 6, 2010 5:53:01 PM (GMT+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn

[cifs-protocol] Numerical value of FLAG_ATTR_REQ_PARTIAL_SET_MEMBER

2010-04-06 Thread Nadezhda Ivanova
Hi, I am not able to find the actual numerical value of FLAG_ATTR_IS_CRITICAL (systemFlagsEx) and FLAG_ATTR_REQ_PARTIAL_SET_MEMBER for systemFlags. I am working on access checks for DRS replication and this blocks my work, so I would appreciate a fast response... Regards, Nadya

Re: [cifs-protocol] Status: SRX091201600038 [MS-ADTS] LDAPControl not applied on add

2009-12-18 Thread Nadezhda Ivanova
Message - From: Bill Wesse bil...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan...@postpath.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Friday, December 18, 2009 5:55:29 PM GMT+0200 Europe;Athens Subject: Status: SRX091201600038 [MS-ADTS] LDAPControl not applied on add

Re: [cifs-protocol] Need some help with LDAP_SERVER_SD_FLAGS_OID control (SRX091119600169)

2009-12-01 Thread Nadezhda Ivanova
...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan...@postpath.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Monday, November 30, 2009 9:51:11 PM GMT+0200 Europe;Athens Subject: RE: [cifs-protocol] Need some help with LDAP_SERVER_SD_FLAGS_OID control (SRX091119600169) Hello Nadya

Re: [cifs-protocol] Need some help with LDAP_SERVER_SD_FLAGS_OID control (SRX091119600169)

2009-11-20 Thread Nadezhda Ivanova
configuration and condition for the control to be taken into account? Best Regards, Nadya - Original Message - From: Bill Wesse bil...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan...@postpath.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Friday, November 20, 2009 7:22:08 PM

[cifs-protocol] Need some help with LDAP_SERVER_SD_FLAGS_OID control

2009-11-19 Thread Nadezhda Ivanova
control LDAP_SERVER_SD_FLAGS_OID with the operation. So, if the control is valid for an LDAP add, what should be the behavior? Best Regards, Nadezhda Ivanova ___ cifs-protocol mailing list cifs-protocol@cifs.org https://lists.samba.org/mailman/listinfo/cifs

Re: [cifs-protocol] Need some help with LDAP_SERVER_SD_FLAGS_OID control (SRX091119600169)

2009-11-19 Thread Nadezhda Ivanova
a bit if you have other priorities. Regards, Nadya - Original Message - From: Bill Wesse bil...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan...@postpath.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Thursday, November 19, 2009 10:23:06 PM GMT+0200 Europe;Athens

Re: [cifs-protocol] Need some help with LDAP_SERVER_SD_FLAGS_OID control (SRX091119600169)

2009-11-19 Thread Nadezhda Ivanova
-protocol-boun...@cifs.org To: bil...@microsoft.com bil...@microsoft.com, Nadezhda Ivanova nadezhda.ivan...@postpath.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Thursday, November 19, 2009 11:30:59 PM GMT+0200 Europe;Athens Subject: Re: [cifs-protocol] Need some help

[cifs-protocol] Fwd: Question about self relative form of SECURITY_DESCRIPTOR

2009-11-18 Thread Nadezhda Ivanova
- Forwarded Message - From: Nadezhda Ivanova nadezhda.ivan...@postpath.com To: doch...@microsoft.com doch...@microsoft.com Cc: cifs-protoc...@samba.org cifs-protoc...@samba.org Sent: Wednesday, November 18, 2009 1:26:01 PM GMT+0200 Europe;Athens Subject: Question about self relative

Re: [cifs-protocol] Question about self relative form of SECURITY_DESCRIPTOR (SRX091118600013)

2009-11-18 Thread Nadezhda Ivanova
To: Nadezhda Ivanova nadezhda.ivan...@postpath.com Cc: cifs-proto...@samba.org cifs-proto...@samba.org Sent: Wednesday, November 18, 2009 6:46:18 PM GMT+0200 Europe;Athens Subject: RE: Question about self relative form of SECURITY_DESCRIPTOR (SRX091118600013) Hello Nadya - here are the results of my

Re: [cifs-protocol] SRX090922600157 : [MS-ADTS] 7.1.1.1 Naming Contexts Domain Admins Permissions

2009-10-26 Thread Nadezhda Ivanova
- From: Bill Wesse bil...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan...@postpath.com Sent: Monday, October 19, 2009 5:42:01 PM GMT+0200 Europe;Athens Subject: RE: SRX090922600157 : [MS-ADTS] 7.1.1.1 Naming Contexts Domain Admins Permissions Good morning – I have returned to work. Just

Re: [cifs-protocol] SRX090922600157 : [MS-ADTS] 7.1.1.1 Naming Contexts Domain Admins Permissions

2009-10-26 Thread Nadezhda Ivanova
a particular FSMO role is assumed - what permissions are added, etc. Do you think you can help me locate these? Thanks for all your help, and your patience! Best Regards, Nadya - Original Message - From: Bill Wesse bil...@microsoft.com To: Nadezhda Ivanova nadezhda.ivan

Re: [cifs-protocol] Question about owner and group defaulting rules in MS-ADTS

2009-08-17 Thread Nadezhda Ivanova
Hi Obaid, Thank you for the attached information. I think it answers the question. Will let you know if something else comes up, but at this point this seems reasonable. Regards, Nadezhda Ivanova From: Obaid Farooqi [mailto:oba...@microsoft.com] Sent: Friday, August 14, 2009 7:12 PM

Re: [cifs-protocol] Status: SRX090805600011 : [MS-ADTS] 5.1.3.2.1 Control Access Rights

2009-08-12 Thread Nadezhda Ivanova
Hi, Thank you for the provided document. This infoirmation appears enough for the time being, though I think we may be sending additional questions about specific access rights in the future. Regards, Nadezhda Ivanova - Original Message - From: Bill Wesse bil...@microsoft.com

Re: [cifs-protocol] Status: SRX090805600011 : [MS-ADTS] 5.1.3.2.1 Control Access Rights

2009-08-11 Thread Nadezhda Ivanova
Hi, I was wandering if there is any progress on this issue? I did not receive anything yesterday... Regards, Nadezhda Ivanova From: Bill Wesse Sent: Thursday, August 06, 2009 8:30 PM To: Nadezhda Ivanova Cc: p...@tridgell.net; cifs-proto...@samba.org Subject: Status: SRX090805600011

Re: [cifs-protocol] Question about owner and group defaulting rules in MS-ADTS

2009-08-11 Thread Nadezhda Ivanova
Hi Obaid, Is there any progress on this issue, or my other enquiry about the security descriptor creation algorithms? It's been a while now and we need this information to be able to include the security implementation in the next alpha of Samba 4. Best Regards, Nadezhda Ivanova From

Re: [cifs-protocol] Information needed about security token default ACL

2009-07-31 Thread Nadezhda Ivanova
Hi Edgar, Thank you for your explanation. It answered a lot of questions, but also raised some more, see below: -Original Message- From: Edgar Olougouna [mailto:edg...@microsoft.com] Sent: Thursday, July 30, 2009 5:37 PM To: Nadezhda Ivanova Cc: 'p...@tridgell.net'; 'cifs-proto

Re: [cifs-protocol] Information needed about security token default ACL

2009-07-28 Thread Nadezhda Ivanova
in the security descriptor of the object. Both conditions must be met in order to use default DACL? It is 1 2, not 1 | 2? Regards, Nadezhda Ivanova -Original Message- From: Obaid Farooqi [mailto:oba...@microsoft.com] Sent: Tuesday, July 28, 2009 12:05 AM To: Nadezhda Ivanova Cc: p...@tridgell.net

[cifs-protocol] Information needed about security token default ACL

2009-07-17 Thread Nadezhda Ivanova
in understanding that this is either the nTSecurityDescriptor attribute provided by the user, or, in the lack thereof, the defaultSecurityDescriptor of the object class? Best Regards, Nadezhda Ivanova ___ cifs-protocol mailing list cifs-protocol

[cifs-protocol] Help regarding the security descriptor creation algorithms

2009-07-10 Thread Nadezhda Ivanova
Forwarding here again as it bounced the first time. From: Nadezhda Ivanova Sent: Friday, July 10, 2009 2:09 PM To: doch...@winse.microsoft.com Cc: cifs-proto...@samba.org; p...@tridgell.net Subject: Help regarding the security descriptor creation algorithms Hi, I have been working