]> git.ipfire.org Git - thirdparty/samba.git/commitdiff
librpc:idl: add windows event 5136 object change
authorDouglas Bagnall <douglas.bagnall@catalyst.net.nz>
Thu, 28 Aug 2025 00:37:13 +0000 (12:37 +1200)
committerDouglas Bagnall <dbagnall@samba.org>
Wed, 3 Sep 2025 02:13:40 +0000 (02:13 +0000)
Signed-off-by: Douglas Bagnall <douglas.bagnall@catalyst.net.nz>
Reviewed-by: Gary Lockyer <gary@catalyst.net.nz>
librpc/idl/windows_event_ids.idl

index f482800d8972662c21a7a10f12a4d2a71e51cb21..04f0cc4672089fe83935c1d27127d4142cc7c62b 100644 (file)
@@ -25,7 +25,17 @@ interface windows_events
                EVT_ID_USER_ADDED_TO_UNIVERSAL_SEC_GROUP                = 4756,
                EVT_ID_USER_REMOVED_FROM_UNIVERSAL_SEC_GROUP            = 4757,
                EVT_ID_USER_ADDED_TO_UNIVERSAL_GROUP                    = 4761,
-               EVT_ID_USER_REMOVED_FROM_UNIVERSAL_GROUP                = 4762
+               EVT_ID_USER_REMOVED_FROM_UNIVERSAL_GROUP                = 4762,
+               /*
+                * Any change to any object will cause event 5136 in
+                * Windows AD -- if that object has a SACL asking for
+                * auditing.
+                *
+                * This event is used for msDS-KeyCredentialLink
+                * changes which do not have a specific event code.
+                */
+               EVT_ID_DIRECTORY_OBJECT_CHANGE                          = 5136
+
        } event_id_type;
 
        /* See https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos#BKMK_ErrorandEvents */