Get and Set DCOM Permissions Using Chef

Viewed 158

I have a need to configure DCOM launch and access permissions for a specific application. Based on another script I found, it appears the raw security descriptor is stored in the registry values AccessPermission and LaunchPermission in the key HKEY_CLASSES_ROOT\AppID\[My-Application-ID].

Instead of having to write my own methods to get and set permissions, is it possible to use methods in the Chef::Win32::Security class? Is there a way I can pass the raw security descriptor data from the registry key to one of these methods to get the ACEs in the DACL?

I was trying something similar below, but I keep getting a Win32 error saying the revision of the security descriptor is unknown.

def dcom_access_permissions
  reg_key = 'AppID\\{12345678-1234-1234-1234-1234567890AB}'
  permissions = ::Win32::Registry::HKEY_CLASSES_ROOT.open(reg_key) do |reg|
    type, value = reg.read('AccessPermission')
    return value
  end

  permissions
end

def dcom_security_descriptor
  raw_sd = dcom_access_permissions
  raw_sd_ptr = ::FFI::MemoryPointer.new raw_sd
  Chef::Win32::Security::SecurityDescriptor.new(raw_sd_ptr)
end

sd = dcom_security_descriptor
sd.dacl

This results in the following error:

---- Begin Win32 API output ----
System Error Code: 1305
System Error Message: The revision level is unknown.
---- End Win32 API output ----
0 Answers
Related