2 Unix SMB/CIFS implementation.
3 Translate BUILTIN names to SIDs and vice versa
4 Copyright (C) Volker Lendecke 2005
6 This program is free software; you can redistribute it and/or modify
7 it under the terms of the GNU General Public License as published by
8 the Free Software Foundation; either version 3 of the License, or
9 (at your option) any later version.
11 This program is distributed in the hope that it will be useful,
12 but WITHOUT ANY WARRANTY; without even the implied warranty of
13 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 GNU General Public License for more details.
16 You should have received a copy of the GNU General Public License
17 along with this program. If not, see <http://www.gnu.org/licenses/>.
21 #include "../libcli/security/security.h"
28 static const struct rid_name_map builtin_aliases
[] = {
29 { BUILTIN_RID_ADMINISTRATORS
, "Administrators" },
30 { BUILTIN_RID_USERS
, "Users" },
31 { BUILTIN_RID_GUESTS
, "Guests" },
32 { BUILTIN_RID_POWER_USERS
, "Power Users" },
33 { BUILTIN_RID_ACCOUNT_OPERATORS
, "Account Operators" },
34 { BUILTIN_RID_SERVER_OPERATORS
, "Server Operators" },
35 { BUILTIN_RID_PRINT_OPERATORS
, "Print Operators" },
36 { BUILTIN_RID_BACKUP_OPERATORS
, "Backup Operators" },
37 { BUILTIN_RID_REPLICATOR
, "Replicator" },
38 { BUILTIN_RID_RAS_SERVERS
, "RAS Servers" },
39 { BUILTIN_RID_PRE_2K_ACCESS
,
40 "Pre-Windows 2000 Compatible Access" },
41 { BUILTIN_RID_REMOTE_DESKTOP_USERS
,
42 "Remote Desktop Users" },
43 { BUILTIN_RID_NETWORK_CONF_OPERATORS
,
44 "Network Configuration Operators" },
45 { BUILTIN_RID_INCOMING_FOREST_TRUST
,
46 "Incoming Forest Trust Builders" },
47 { BUILTIN_RID_PERFMON_USERS
,
48 "Performance Monitor Users" },
49 { BUILTIN_RID_PERFLOG_USERS
,
50 "Performance Log Users" },
51 { BUILTIN_RID_AUTH_ACCESS
,
52 "Windows Authorization Access Group" },
53 { BUILTIN_RID_TS_LICENSE_SERVERS
,
54 "Terminal Server License Servers" },
55 { BUILTIN_RID_DISTRIBUTED_COM_USERS
,
56 "Distributed COM Users" },
57 { BUILTIN_RID_CRYPTO_OPERATORS
,
58 "Cryptographic Operators" },
59 { BUILTIN_RID_EVENT_LOG_READERS
,
60 "Event Log Readers" },
61 { BUILTIN_RID_CERT_SERV_DCOM_ACCESS
,
62 "Certificate Service DCOM Access" },
65 /*******************************************************************
66 Look up a rid in the BUILTIN domain
67 ********************************************************************/
68 bool lookup_builtin_rid(TALLOC_CTX
*mem_ctx
, uint32_t rid
, const char **name
)
70 const struct rid_name_map
*aliases
= builtin_aliases
;
72 while (aliases
->name
!= NULL
) {
73 if (rid
== aliases
->rid
) {
74 *name
= talloc_strdup(mem_ctx
, aliases
->name
);
83 /*******************************************************************
84 Look up a name in the BUILTIN domain
85 ********************************************************************/
86 bool lookup_builtin_name(const char *name
, uint32_t *rid
)
88 const struct rid_name_map
*aliases
= builtin_aliases
;
90 while (aliases
->name
!= NULL
) {
91 if (strequal(name
, aliases
->name
)) {
101 /*****************************************************************
102 Return the name of the BUILTIN domain
103 *****************************************************************/
105 const char *builtin_domain_name(void)
110 /*****************************************************************
111 Check if the SID is the builtin SID (S-1-5-32).
112 *****************************************************************/
114 bool sid_check_is_builtin(const struct dom_sid
*sid
)
116 return dom_sid_equal(sid
, &global_sid_Builtin
);
119 /*****************************************************************
120 Check if the SID is one of the builtin SIDs (S-1-5-32-a).
121 *****************************************************************/
123 bool sid_check_is_in_builtin(const struct dom_sid
*sid
)
125 struct dom_sid dom_sid
;
127 sid_copy(&dom_sid
, sid
);
128 sid_split_rid(&dom_sid
, NULL
);
130 return sid_check_is_builtin(&dom_sid
);
133 /********************************************************************
134 Check if the SID is one of the well-known builtin SIDs (S-1-5-32-x)
135 *********************************************************************/
137 bool sid_check_is_wellknown_builtin(const struct dom_sid
*sid
)
139 struct dom_sid dom_sid
;
140 const struct rid_name_map
*aliases
= builtin_aliases
;
143 sid_copy(&dom_sid
, sid
);
144 sid_split_rid(&dom_sid
, &rid
);
146 if (!sid_check_is_builtin(&dom_sid
)) {
150 while (aliases
->name
!= NULL
) {
151 if (aliases
->rid
== rid
) {