Article ID: 188760
Article Last Modified on 10/30/2006
Container Object Objects Contained ----------------------------------------------- Directory Files/Directories Registry Key Registry Subkeys Windowstation Desktop Printer Print JobsWindows NT, Windows 2000, and Windows XP support Access Control List (ACL) inheritance. This means that when a new object is created within a container object, the new object inherits permissions (access control entries marked as inheritable) from the parent container object by default.
102102 How To Add an Access-Allowed ACE to a File
{
// You can add this after step 14 of Q102102, which demonstrates adding
// an Access Allowed ACE to a DACL.
BYTE bAceFlags = CONTAINER_INHERIT_ACE | OBJECT_INHERIT_ACE;
// Get pointer to ACE you just added, so you can change the AceFlags.
if (!GetAce(pNewACL,
newAceIndex,
&pTempAce))
{
_tprintf(TEXT("GetAce() failed. Error %d\n"),
GetLastError());
__leave;
}
// Set AceFlags member.
((ACCESS_ALLOWED_ACE *)pTempAce)->Header.AceFlags = bAceFlags;
}
This extra step is necessary because the AddAccessAllowedAce() API does not
have a parameter to specify this attribute of a new ACE. Windows 2000 and Windows XP introduces the AddAccessAllowedAceEx() API, which does have a parameter to specify the AceFlags member of a new ACE. Applications should check for the existence of AddAccessAllowedAceEx() in Advapi32.dll by calling the LoadLibrary() and GetProcAddress() APIs.
{
BYTE bAceFlags = CONTAINER_INHERIT_ACE | OBJECT_INHERIT_ACE;
DWORD sidlen = GetLengthSid(pUserSID);
ACCESS_ALLOWED_ACE *pAce = (ACCESS_ALLOWED_ACE *)
myheapalloc(sizeof(ACCESS_ALLOWED_ACE) + sidlen - sizeof(DWORD));
if (!pAce) {
_tprintf(TEXT("HeapAlloc() failed. Error %d\n"), GetLastError());
__leave;
}
// Fill in ACCESS_ALLOWED_ACE structure.
pAce->Mask = dwAccessMask;
pAce->Header.AceType = ACCESS_ALLOWED_ACE_TYPE;
pAce->Header.AceFlags = bAceFlags;
pAce->Header.AceSize = sizeof(ACCESS_ALLOWED_ACE)
+ sidlen - sizeof(DWORD);
memcpy (&(pAce->SidStart), pUserSID, sidlen);
if (!AddAce(pNewACL, ACL_REVISION, MAXDWORD,
pAce, pAce->Header.AceSize))
{
_tprintf(TEXT("AddAce() failed. Error %d\n"),
GetLastError());
myheapfree(pAce);
__leave;
}
myheapfree(pAce);
}
Additional query words: directory sid special security printer
Keywords: kbhowto kbapi kbkernbase kbsecurity kbacl KB188760