From: Tim Beale Date: Tue, 29 Jan 2019 00:25:55 +0000 (+1300) Subject: netcmd: Improve error handling of gpo aclcheck as non-admin X-Git-Tag: ldb-1.6.1~249 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=5bfad1b2b08031b99834c9ca39c1900d52c8eb0d;p=thirdparty%2Fsamba.git netcmd: Improve error handling of gpo aclcheck as non-admin Reading the nTSecurityDescriptor attribute over LDAP requires admin creds. However, if you don't specify admin creds, then you get an error like this: bin/samba-tool gpo aclcheck ERROR(): uncaught exception - 'No such element' File "bin/python/samba/netcmd/__init__.py", line 184, in _run return self.run(*args, **kwargs) File "bin/python/samba/netcmd/gpo.py", line 1536, in run ds_sd_ndr = m['nTSecurityDescriptor'][0] This patch adds an explicit check/error message to make the problem clearer. Signed-off-by: Tim Beale Reviewed-by: Andrew Bartlett --- diff --git a/python/samba/netcmd/gpo.py b/python/samba/netcmd/gpo.py index 1b5e927f633..95fe5d6d439 100644 --- a/python/samba/netcmd/gpo.py +++ b/python/samba/netcmd/gpo.py @@ -1533,6 +1533,10 @@ class cmd_aclcheck(GPOCommand): fs_sd = conn.get_acl(sharepath, security.SECINFO_OWNER | security.SECINFO_GROUP | security.SECINFO_DACL, security.SEC_FLAG_MAXIMUM_ALLOWED) + if 'nTSecurityDescriptor' not in m: + raise CommandError("Could not read nTSecurityDescriptor. " + "This requires an Administrator account") + ds_sd_ndr = m['nTSecurityDescriptor'][0] ds_sd = ndr_unpack(security.descriptor, ds_sd_ndr).as_sddl()