delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2010/04/19/19:02:51

X-Recipient: archive-cygwin AT delorie DOT com
X-SWARE-Spam-Status: No, hits=-1.7 required=5.0 tests=BAYES_00,TW_FD,TW_PR,TW_RV
X-Spam-Check-By: sourceware.org
Date: Mon, 19 Apr 2010 17:02:39 -0600
From: Tom Schutter <tschutter AT firstam DOT com>
To: cygwin AT cygwin DOT com
Subject: Re: group membership problems with ssh PubKey
Message-ID: <20100419230239.GM5284@proxix.com>
References: <20100416201433 DOT GB5284 AT proxix DOT com>
MIME-Version: 1.0
In-Reply-To: <20100416201433.GB5284@proxix.com>
User-Agent: Mutt/1.5.20 (2009-06-14)
X-IsSubscribed: yes
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

On Fri 2010-04-16 15:14, Tom Schutter wrote:
> This is a problem that I am having with all of my 1.7 installations.
> 
> If I bring up a local shell and list my group memberships:
> 
> lemon:~$ groups
> Domain Users Administrators Users FDSV-DL-FASS FDSV-DL-Proxix FDSV-GG-Bugzilla FDSV-GG-FASS FDSV-GG-Jabber FDSV-GG-Nagios FDSV-GG-PrxAAPCAdmins FDSV-GG-PrxBLD FDSV-GG-PrxPCAdmins FDSV-GG-ShareFASSSharedRW FDSV-GG-ShareFwiseLF FDSV-GG-ShareFwiseRO FDSV-GG-ShareImages3RO FDSV-GG-ShareResourcesLF FDSV-GG-ShareResourcesRO FDSV-GG-TikiDev
> 
> Notice that I am a member of the Administrators group.  This is because I am a member of the FDSV-GG-PrxBLD group, which has been added to the local Administrators group.
> 
> Now if I login via SSH using PubKey authentication and list my group memberships:
> 
> lemon:~$ groups
> Domain Users Users FDSV-DL-Proxix FDSV-GG-Bugzilla FDSV-GG-FASS FDSV-GG-Jabber FDSV-GG-Nagios FDSV-GG-PrxAAPCAdmins FDSV-GG-PrxBLD FDSV-GG-PrxPCAdmins FDSV-GG-TikiDev
> 
> I am a member of the FDSV-GG-PrxBLD group, but not the local Administrators group.
> 
> I am using cyglsa.
> 
> I am not using cygserver.
> 
> sshd is running as the domain user fdsv-sa-prx-sshdsrvr.  These are the user rights for that user:
> 
> lemon:~$ editrights -l -u fdsv-sa-prx-sshdsrvr
> SeCreateTokenPrivilege
> SeTcbPrivilege
> SeIncreaseQuotaPrivilege
> SeAssignPrimaryTokenPrivilege
> SeServiceLogonRight
> 
> The fdsv-sa-prx-sshdsrvr user is in /etc/passwd:
> 
> lemon:~$ grep fdsv-sa-prx-sshdsrvr /etc/passwd
> fdsv-sa-prx-sshdsrvr:unused:18846:10513:Service Account, Prx-SSHDSrvr,U-FLOODDATA\fdsv-sa-prx-sshdsrvr,S-1-5-21-2555220796-769361577-1294736918-8846:/home/fdsv-sa-prx-sshdsrvr:/bin/bash
> 
> I have blanked any password stored in the registry by specifying a blank password to "passwd -R".
> 
> I have read and I think I understand http://cygwin.com/cygwin-ug-net/ntsec.html
> 
> It looks to me like this is an issue of being an "indirect" member of the Administrators group via the domain FDSV-GG-PrxBLD group.

Does anyone have a clue on this one?  Larry Hall's response was based upon a misreading of the original email.

-- 
Tom Schutter
First American Spatial Solutions
303-440-7272 x6822
512-977-6822

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019