Setting DACL of registry key using SDDL

Viewed 203

I am trying to replace a old script using regini.exe with the Set-Acl Powershell Cmdlet.

regini.exe is called on a file with the following contents:

\registry\machine\SOFTWARE\WOW6432Node\mykey [1 5]

This disables inheritence and gives full access to "CREATOR OWNER" and "Administrators". If I retrieve the SDDL for the Security Descriptor via Get-Acl, I get the following result: O:SYG:SYD:P(A;CI;KA;;;CO)(A;CI;KA;;;BA)

The following script is my idea for a powershell based version:

$keyAcl = New-Object System.Security.AccessControl.RegistrySecurity
$keyAcl.SetSecurityDescriptorSddlForm('D:P(A;CI;KA;;;CO)(A;CI;KA;;;BA)')
Set-Acl -AclObject $keyAcl -Path 'HKLM:\Software\WOW6432Node\mykey'

However, if I retrieve the Security Descriptor SDDL after running the script, I get a different result: O:SYG:SYD:PAI(A;CIIO;KA;;;CO)(A;;KA;;;SY)(A;CI;KA;;;BA)

Notice the following changes:

  • AI was added, which forces the inheritance to the exiting keys
  • The entry for "CREATOR OWNER" got a IO flag, which limits it to subkeys
  • An entry (A;;KA;;;SY) was added, which gives SYSTEM full access to the key itsself

As far as I can tell this Security Descriptor should have a similar effect, since System is the owner. However, I would prefer if the new Powershell-based script did exactly the same as the old regini-based script.

Why does DACL created by Set-Acl differ from the one i specified? Is there a way to force Set-Acl to set the exact DACL?

0 Answers
Related