From 8f8a9f01909ba29e2b781310baeeaaddc3f15f0d Mon Sep 17 00:00:00 2001 From: "Gerald W. Carter" Date: Tue, 22 Apr 2008 10:09:40 -0500 Subject: Moving docs tree to docs-xml to make room for generated docs in the release tarball. (This used to be commit 9f672c26d63955f613088489c6efbdc08b5b2d14) --- docs-xml/smbdotconf/logon/enableprivileges.xml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) create mode 100644 docs-xml/smbdotconf/logon/enableprivileges.xml (limited to 'docs-xml/smbdotconf/logon/enableprivileges.xml') diff --git a/docs-xml/smbdotconf/logon/enableprivileges.xml b/docs-xml/smbdotconf/logon/enableprivileges.xml new file mode 100644 index 0000000000..3e958e0ce9 --- /dev/null +++ b/docs-xml/smbdotconf/logon/enableprivileges.xml @@ -0,0 +1,26 @@ + + + + This parameter controls whether or not smbd will honor privileges assigned to specific SIDs via either + net rpc rights or one of the Windows user and group manager tools. This parameter is + enabled by default. It can be disabled to prevent members of the Domain Admins group from being able to + assign privileges to users or groups which can then result in certain smbd operations running as root that + would normally run under the context of the connected user. + + + + An example of how privileges can be used is to assign the right to join clients to a Samba controlled + domain without providing root access to the server via smbd. + + + + Please read the extended description provided in the Samba HOWTO documentation. + + + +yes + -- cgit