I have a need to configure DCOM launch and access permissions for a specific application. Based on another script I found, it appears the raw security descriptor is stored in the registry values AccessPermission and LaunchPermission in the key HKEY_CLASSES_ROOT\AppID\[My-Application-ID].
Instead of having to write my own methods to get and set permissions, is it possible to use methods in the Chef::Win32::Security class? Is there a way I can pass the raw security descriptor data from the registry key to one of these methods to get the ACEs in the DACL?
I was trying something similar below, but I keep getting a Win32 error saying the revision of the security descriptor is unknown.
def dcom_access_permissions
reg_key = 'AppID\\{12345678-1234-1234-1234-1234567890AB}'
permissions = ::Win32::Registry::HKEY_CLASSES_ROOT.open(reg_key) do |reg|
type, value = reg.read('AccessPermission')
return value
end
permissions
end
def dcom_security_descriptor
raw_sd = dcom_access_permissions
raw_sd_ptr = ::FFI::MemoryPointer.new raw_sd
Chef::Win32::Security::SecurityDescriptor.new(raw_sd_ptr)
end
sd = dcom_security_descriptor
sd.dacl
This results in the following error:
---- Begin Win32 API output ----
System Error Code: 1305
System Error Message: The revision level is unknown.
---- End Win32 API output ----