I am trying to replace a old script using regini.exe with the Set-Acl Powershell Cmdlet.
regini.exe is called on a file with the following contents:
\registry\machine\SOFTWARE\WOW6432Node\mykey [1 5]
This disables inheritence and gives full access to "CREATOR OWNER" and "Administrators". If I retrieve the SDDL for the Security Descriptor via Get-Acl, I get the following result: O:SYG:SYD:P(A;CI;KA;;;CO)(A;CI;KA;;;BA)
The following script is my idea for a powershell based version:
$keyAcl = New-Object System.Security.AccessControl.RegistrySecurity
$keyAcl.SetSecurityDescriptorSddlForm('D:P(A;CI;KA;;;CO)(A;CI;KA;;;BA)')
Set-Acl -AclObject $keyAcl -Path 'HKLM:\Software\WOW6432Node\mykey'
However, if I retrieve the Security Descriptor SDDL after running the script, I get a different result: O:SYG:SYD:PAI(A;CIIO;KA;;;CO)(A;;KA;;;SY)(A;CI;KA;;;BA)
Notice the following changes:
AIwas added, which forces the inheritance to the exiting keys- The entry for "CREATOR OWNER" got a
IOflag, which limits it to subkeys - An entry
(A;;KA;;;SY)was added, which gives SYSTEM full access to the key itsself
As far as I can tell this Security Descriptor should have a similar effect, since System is the owner. However, I would prefer if the new Powershell-based script did exactly the same as the old regini-based script.
Why does DACL created by Set-Acl differ from the one i specified? Is there a way to force Set-Acl to set the exact DACL?