Bug 8500 - A member of the group Account Operators cannot create machine accounts
Summary: A member of the group Account Operators cannot create machine accounts
Status: NEW
Alias: None
Product: Samba 4.1 and newer
Classification: Unclassified
Component: AD: LDB/DSDB/SAMDB (show other bugs)
Version: unspecified
Hardware: x64 All
: P5 normal (vote)
Target Milestone: ---
Assignee: Samba QA Contact
QA Contact: samba4-qa@samba.org
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-09-29 13:07 UTC by Dirk Gouders
Modified: 2020-05-21 01:33 UTC (History)
2 users (show)

See Also:


Attachments
Client creates computer account. (49.38 KB, application/octet-stream)
2011-09-29 13:07 UTC, Dirk Gouders
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Dirk Gouders 2011-09-29 13:07:50 UTC
Created attachment 6967 [details]
Client creates computer account.

In Win2k we used an account that is member of the group Account Operators
to join and rejoin the domain, i.e. create and modify machine accounts.

With Samba being member of the group Account Operators does not seem to be sufficiant to create machine accounts, such a user can only work on existing
machine accounts.

I captured the network traffic from/to the client machine on a Win2k Server
while the client uses such an account to join the domain from a
machine that has no account on the DC.
Comment 1 Matthieu Patou 2011-09-29 17:45:17 UTC
Can you re-explain which se- right should grant the capability to do this.
I'm pretty sure we don't check this right and have a simple if user had administrative rights
Comment 2 Dirk Gouders 2011-09-29 21:10:18 UTC
(In reply to comment #1)
> Can you re-explain which se- right should grant the capability to do this.
> I'm pretty sure we don't check this right and have a simple if user had
> administrative rights

In w2k it was/is sufficient to be a member of the group Account Operators.
I was just testing if it helps to have the right SeMachineAccountPrivileg
to ge these privileges but it did not help.