SID Strings

In the security descriptor definition language (SDDL), security descriptor string use SID strings for the following components of a security descriptor:

  • Owner
  • Primary group
  • The trustee in an ACE

A SID string in a security descriptor string can use either the standard string representation of a SID (S-R-I-S-S…) or one of the string constants defined in Sddl.h. For more information about the standard SID string notation, see SID Components.

The following SID string constants for well-known SIDs are defined in Sddl.h. For information about the corresponding relative IDs (RIDs), see Well-known SIDs.

SID string Constant in Sddl.h Account alias and corresponding RID

"AN"

SDDL_ANONYMOUS

Anonymous logon. The corresponding RID is SECURITY_ANONYMOUS_LOGON_RID.

"AO"

SDDL_ACCOUNT_OPERATORS

Account operators. The corresponding RID is DOMAIN_ALIAS_RID_ACCOUNT_OPS.

"AU"

SDDL_AUTHENTICATED_USERS

Authenticated users. The corresponding RID is SECURITY_AUTHENTICATED_USER_RID.

"BA"

SDDL_BUILTIN_ADMINISTRATORS

Built-in administrators. The corresponding RID is DOMAIN_ALIAS_RID_ADMINS.

"BG"

SDDL_BUILTIN_GUESTS

Built-in guests. The corresponding RID is DOMAIN_ALIAS_RID_GUESTS.

"BO"

SDDL_BACKUP_OPERATORS

Backup operators. The corresponding RID is DOMAIN_ALIAS_RID_BACKUP_OPS.

"BU"

SDDL_BUILTIN_USERS

Built-in users. The corresponding RID is DOMAIN_ALIAS_RID_USERS.

"CA"

SDDL_CERT_SERV_ADMINISTRATORS

Certificate publishers. The corresponding RID is DOMAIN_GROUP_RID_CERT_ADMINS.

"CD"

SDDL_CERTSVC_DCOM_ACCESS

Users who can connect to certification authorities using Distributed Component Object Model (DCOM). The corresponding RID is DOMAIN_ALIAS_RID_CERTSVC_DCOM_ACCESS_GROUP.

"CG"

SDDL_CREATOR_GROUP

Creator group. The corresponding RID is SECURITY_CREATOR_GROUP_RID.

"CO"

SDDL_CREATOR_OWNER

Creator owner. The corresponding RID is SECURITY_CREATOR_OWNER_RID.

"DA"

SDDL_DOMAIN_ADMINISTRATORS

Domain administrators. The corresponding RID is DOMAIN_GROUP_RID_ADMINS.

"DC"

SDDL_DOMAIN_COMPUTERS

Domain computers. The corresponding RID is DOMAIN_GROUP_RID_COMPUTERS.

"DD"

SDDL_DOMAIN_DOMAIN_CONTROLLERS

Domain controllers. The corresponding RID is DOMAIN_GROUP_RID_CONTROLLERS.

"DG"

SDDL_DOMAIN_GUESTS

Domain guests. The corresponding RID is DOMAIN_GROUP_RID_GUESTS.

"DU"

SDDL_DOMAIN_USERS

Domain users. The corresponding RID is DOMAIN_GROUP_RID_USERS.

"EA"

SDDL_ENTERPRISE_ADMINS

Enterprise administrators. The corresponding RID is DOMAIN_GROUP_RID_ENTERPRISE_ADMINS.

"ED"

SDDL_ENTERPRISE_DOMAIN_CONTROLLERS

Enterprise domain controllers. The corresponding RID is SECURITY_SERVER_LOGON_RID.

"HI"

SDDL_ML_HIGH

High integrity level. The corresponding RID is SECURITY_MANDATORY_HIGH_RID.

"IU"

SDDL_INTERACTIVE

Interactively logged-on user. This is a group identifier added to the token of a process when it was logged on interactively. The corresponding logon type is LOGON32_LOGON_INTERACTIVE. The corresponding RID is SECURITY_INTERACTIVE_RID.

"LA"

SDDL_LOCAL_ADMIN

Local administrator. The corresponding RID is DOMAIN_USER_RID_ADMIN.

"LG"

SDDL_LOCAL_GUEST

Local guest. The corresponding RID is DOMAIN_USER_RID_GUEST.

"LS"

SDDL_LOCAL_SERVICE

Local service account. The corresponding RID is SECURITY_LOCAL_SERVICE_RID.

"LW"

SDDL_ML_LOW

Low integrity level. The corresponding RID is SECURITY_MANDATORY_LOW_RID.

"ME"

SDDL_MLMEDIUM

Medium integrity level. The corresponding RID is SECURITY_MANDATORY_MEDIUM_RID.

"MU"

SDDL_PERFMON_USERS

Performance Monitor users.

"NO"

SDDL_NETWORK_CONFIGURATION_OPS

Network configuration operators. The corresponding RID is DOMAIN_ALIAS_RID_NETWORK_CONFIGURATION_OPS.

"NS"

SDDL_NETWORK_SERVICE

Network service account. The corresponding RID is SECURITY_NETWORK_SERVICE_RID.

"NU"

SDDL_NETWORK

Network logon user. This is a group identifier added to the token of a process when it was logged on across a network. The corresponding logon type is LOGON32_LOGON_NETWORK. The corresponding RID is SECURITY_NETWORK_RID.

"PA"

SDDL_GROUP_POLICY_ADMINS

Group Policy administrators. The corresponding RID is DOMAIN_GROUP_RID_POLICY_ADMINS.

"PO"

SDDL_PRINTER_OPERATORS

Printer operators. The corresponding RID is DOMAIN_ALIAS_RID_PRINT_OPS.

"PS"

SDDL_PERSONAL_SELF

Principal self. The corresponding RID is SECURITY_PRINCIPAL_SELF_RID.

"PU"

SDDL_POWER_USERS

Power users. The corresponding RID is DOMAIN_ALIAS_RID_POWER_USERS.

"RC"

SDDL_RESTRICTED_CODE

Restricted code. This is a restricted token created using the CreateRestrictedToken function. The corresponding RID is SECURITY_RESTRICTED_CODE_RID.

"RD"

SDDL_REMOTE_DESKTOP

Terminal server users. The corresponding RID is DOMAIN_ALIAS_RID_REMOTE_DESKTOP_USERS.

"RE"

SDDL_REPLICATOR

Replicator. The corresponding RID is DOMAIN_ALIAS_RID_REPLICATOR.

"RO"

SDDL_ENTERPRISE_RO_DCs

Enterprise Read-only domain controllers. The corresponding RID is DOMAIN_GROUP_RID_ENTERPRISE_READONLY_DOMAIN_CONTROLLERS.

"RS"

SDDL_RAS_SERVERS

RAS servers group. The corresponding RID is DOMAIN_ALIAS_RID_RAS_SERVERS.

"RU"

SDDL_ALIAS_PREW2KCOMPACC

Alias to grant permissions to accounts that use applications compatible with operating systems previous to Windows 2000. The corresponding RID is DOMAIN_ALIAS_RID_PREW2KCOMPACCESS.

"SA"

SDDL_SCHEMA_ADMINISTRATORS

Schema administrators. The corresponding RID is DOMAIN_GROUP_RID_SCHEMA_ADMINS.

"SI"

SDDL_ML_SYSTEM

System integrity level. The corresponding RID is SECURITY_MANDATORY_SYSTEM_RID.

"SO"

SDDL_SERVER_OPERATORS

Server operators. The corresponding RID is DOMAIN_ALIAS_RID_SYSTEM_OPS.

"SU"

SDDL_SERVICE

Service logon user. This is a group identifier added to the token of a process when it was logged as a service. The corresponding logon type is LOGON32_LOGON_SERVICE. The corresponding RID is SECURITY_SERVICE_RID.

"SY"

SDDL_LOCAL_SYSTEM

Local system. The corresponding RID is SECURITY_LOCAL_SYSTEM_RID.

"WD"

SDDL_EVERYONE

Everyone. The corresponding RID is SECURITY_WORLD_RID.

 

The ConvertSidToStringSid and ConvertStringSidToSid functions always use the standard SID string notation and do not support SDDL SID string constants.

For more information about well-known SIDs, see Well-known SIDs.

Related topics

[MS-DTYP]: Security Descriptor Description Language
资源下载链接为: https://pan.quark.cn/s/3d8e22c21839 随着 Web UI 框架(如 EasyUI、JqueryUI、Ext、DWZ 等)的不断发展与成熟,系统界面的统一化设计逐渐成为可能,同时代码生成器也能够生成符合统一规范的界面。在这种背景下,“代码生成 + 手工合并”的半智能开发模式正逐渐成为新的开发趋势。通过代码生成器,单表数据模型以及一对多数据模型的增删改查功能可以被直接生成并投入使用,这能够有效节省大约 80% 的开发工作量,从而显著提升开发效率。 JEECG(J2EE Code Generation)是一款基于代码生成器的智能开发平台。它引领了一种全新的开发模式,即从在线编码(Online Coding)到代码生成器生成代码,再到手工合并(Merge)的智能开发流程。该平台能够帮助开发者解决 Java 项目中大约 90% 的重复性工作,让开发者可以将更多的精力集中在业务逻辑的实现上。它不仅能够快速提高开发效率,帮助公司节省大量的人力成本,同时也保持了开发的灵活性。 JEECG 的核心宗旨是:对于简单的功能,可以通过在线编码配置来实现;对于复杂的功能,则利用代码生成器生成代码后,再进行手工合并;对于复杂的流程业务,采用表单自定义的方式进行处理,而业务流程则通过工作流来实现,并且可以扩展出任务接口,供开发者编写具体的业务逻辑。通过这种方式,JEECG 实现了流程任务节点和任务接口的灵活配置,既保证了开发的高效性,又兼顾了项目的灵活性和可扩展性。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值