Bug 9978 - SEC_PRIV_MACHINE_ACCOUNT is not honored
SEC_PRIV_MACHINE_ACCOUNT is not honored
Status: RESOLVED DUPLICATE of bug 10656
Product: Samba 4.0
Classification: Unclassified
Component: AD: LDB/DSDB/SAMDB
4.0.6
All All
: P5 normal
: ---
Assigned To: Andrew Bartlett
Samba QA Contact
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-06-29 06:42 UTC by Matthieu Patou
Modified: 2015-10-13 21:23 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matthieu Patou 2013-06-29 06:42:21 UTC
Default domain policy for domain controller grants this privilege to all authenticated users, as we don't parse GPO for the moment this is not set.
But even if you modify manually the privilege.ldb to grant this privilege to authenticatedusers then a simple users can't create a computer using for instance an LDAP add request (in windows 2012 this is working).
Comment 1 Andrew Bartlett 2015-10-13 21:23:29 UTC
More detail is in this later bug, so marked as duplicate

*** This bug has been marked as a duplicate of bug 10656 ***