The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

ActiveDirectory Question (eew!) by waveydavey2007-05-09 02:29:48
  yes it is possible by errtu2007-05-09 03:39:51
    On the 15-minute thing: by bwkaz 2007-05-09 05:18:16
Are you using the SID directly? (E.g. by getting the current ACL, then calling ConvertSecurityDescriptorToStringSecurityDescriptor (yes, that is actually an API function), then appending the SDDL string for the new ACE (which will use the SID, not the user's name) to the string, converting the new string back to a security descriptor, and setting it onto the directory.)

I can see the user's name not resolving to their SID for 15 minutes if you have two DCs, because the user-creation process might be talking to a different DC than the username-resolving process, and the DCs would need to replicate the new user. But the SID should be valid at any time (and actually *any* SID should be valid at any time, whether a user exists for it or not).

OTOH, if this is web-based, you may not have access to the "raw" SDDL/ACL functions; that would be a reason you may not be doing this. :-)
[ Reply ]
      thanks for the info :) by errtu2007-05-10 02:03:14

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)