delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2006/01/18/11:41:52

X-Spam-Check-By: sourceware.org
From: "Dave Korn" <dave DOT korn AT artimi DOT com>
To: <cygwin AT cygwin DOT com>
Subject: RE: Wich privileges required by ssh-host-config running user?
Date: Wed, 18 Jan 2006 16:41:08 -0000
MIME-Version: 1.0
In-Reply-To: <43CE6C0D.7050902@equate.dyndns.org>
Message-ID: <SERRANOP9ww1WySvX5w000001bc@SERRANO.CAM.ARTIMI.COM>
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Chris Taylor wrote:
> Dave Korn wrote:
>> Chris Taylor wrote:
>> 
>>> Dave Korn wrote:
>> 
>> 
>>>>  Simplest workaround would be to always join the machine to the domain
>>>> first and install cygwin second.
>>>> 
>>> 
>>> And to install as the domain administrator, not the local admin,
>>> otherwise you run into this problem, as the OP has done.
>> 
>> 
>>   Probably a domain user would suffice.  It might be best if the domain
>> user account was made a "Power User" in the machine's local user
>> accounts. 

> I'm not sure that power users have the ability to change ownership in
> this way.. 

  Actually, I'm not sure either.  If "Power Users" isn't enough, it would need
to be a local admin.

> It may be that you would be required to use a domain
> administrator account to install and to set up any services you wished
> to use, though I could be mistaken. I'd have to test it to see.

  No, the issue is not what rights you have in the domain, but what rights the
domain user has over the local machine.  Domain admins are automatically
admins over the local machine, and domain users are not, but domain users can
be made into local admins by anyone with admin rights over the machine (such
as the local admin) and it doesn't require domain admin rights.  

  Basically, nothing you need to do to an individual machine should ever need
domain admin rights.  It's about _local_ rights.


    cheers,
      DaveK
-- 
Can't think of a witty .sigline today....


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019