Leaked source code of windows server 2003
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

108 lines
4.5 KiB

  1. ; (c) Microsoft Corporation 1997-2002
  2. ;
  3. ; Security Configuration Template for Security Configuration Editor
  4. ;
  5. ; Template Name: ProfSec.INF
  6. ; Template Version: 05.20.DW.0000
  7. ;
  8. ; Default Security for Profiles Directory
  9. [version]
  10. signature="$CHICAGO$"
  11. revision=1
  12. DriverVer=10/01/2002,5.2.3688.0
  13. [File Security]
  14. ;
  15. ; Default User Profile, overwrite existing DACLs on all subfolders/files
  16. ;
  17. "%DefaultUserProfile%", 2, "D:(A;OICIID;FA;;;SY)(A;OICIID;FA;;;BA)(A;OICIID;GXGR;;;BU)(A;OICIID;GXGR;;;PU)(A;OICIID;GXGR;;;WD)"
  18. ;
  19. ; All Users Profile, set on the folder only
  20. ;
  21. "%AllUsersProfile%", 4, %Default_AllUsers%
  22. ;
  23. ; Desktop, Favorites, Start Menu and Templates, inherite from all user's profile and overwrite existing DACL
  24. ;
  25. "%Common_Desktop%", 2, %Default_Inherited%
  26. "%Common_Favorites%", 2, %Default_Inherited%
  27. "%Common_StartMenu%", 2, %Default_Inherited%
  28. "%Common_Templates%", 2, %Default_Inherited%
  29. ;
  30. ; ntuser.pol, inherited from all user's folder
  31. ;
  32. "%AllUsersProfile%\ntuser.pol", 2, %Default_Inherited%
  33. ;
  34. ; Documents, writable to user, OVERWRITE existing DACLs on all subfolders/files
  35. ; Note: Since FAT doesn't have owner information, the CO(F) ace doens't make effect after the conversion,
  36. ; The owner of the documents has to ask the admin to manually reset the document ownership.
  37. ;
  38. "%Common_Docs%", 2, "D:P(A;OICI;FA;;;SY)(A;OICI;FA;;;BA)(A;OICIIO;GA;;;CO)(A;OICI;0x1301bf;;;PU)(A;OICI;0x1200a9;;;BU)(A;CI;DCLCRPCR;;;BU)"
  39. "%Common_Docs%\Desktop.ini", 2, %Default_AllUsers%
  40. ;
  41. ; App Data, writable to user, set on the folder itself, all the subfolders/files that not specify in this file will remain
  42. ; the unchanged, i.e. Everyone(F) after FAT->NTFS conversion.
  43. ;
  44. "%Common_AppData%", 4, "D:P(A;OICI;FA;;;SY)(A;OICI;FA;;;BA)(A;OICIIO;GA;;;CO)(A;OICI;0x1301bf;;;PU)(A;OICI;0x1200a9;;;BU)(A;CI;DCLCRPCR;;;BU)"
  45. "%Common_AppData%\Desktop.ini", 2, %Default_AllUsers%
  46. ;
  47. ; App Data\Microsoft, same as all user's folder
  48. ;
  49. "%Common_AppData%\Microsoft", 4, %Default_AllUsers%
  50. "%Common_AppData%\Microsoft\Network", 4, %Default_Inherited%
  51. "%Common_AppData%\Microsoft\Network\Downloader", 2, "D:P(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)"
  52. "%Common_AppData%\Microsoft\Network\Connections", 2, %Default_Inherited%
  53. "%Common_AppData%\Microsoft\Network\Connections\Pbk\cm", 2, "D:P(A;OICI;0x1301ff;;;WD)"
  54. "%Common_AppData%\Microsoft\Network\Connections\Pbk\rasphone.pbk", 2, "D:P(A;;0x1301ff;;;WD)"
  55. "%Common_AppData%\Microsoft\Network\Connections\Pbk\_cmphone.pbk", 2, "D:P(A;;0x1301ff;;;WD)"
  56. "%Common_AppData%\Microsoft\User Account Pictures", 2, %Default_Inherited%
  57. "%Common_AppData%\Microsoft\Crypto", 4, %Default_Inherited%
  58. "%Common_AppData%\Microsoft\Crypto\RSA", 4, %Default_Inherited%
  59. "%Common_AppData%\Microsoft\Crypto\RSA\MachineKeys", 4, "D:P(A;;0x12019f;;;WD)(A;;FA;;;BA)"
  60. "%Common_AppData%\Microsoft\Crypto\DSS", 4, %Default_Inherited%
  61. "%Common_AppData%\Microsoft\Crypto\DSS\MachineKeys", 4, "D:P(A;;0x12019f;;;WD)(A;;FA;;;BA)"
  62. "%Common_AppData%\Microsoft\Windows NT", 4, %Default_Inherited%
  63. "%Common_AppData%\Microsoft\Windows NT\MSFax", 4, %Default_Inherited%
  64. "%Common_AppData%\Microsoft\Windows NT\MSFax\Inbox", 2, "D:PAI(A;OICI;FA;;;BA)(A;OICI;FA;;;NS)"
  65. "%Common_AppData%\Microsoft\Windows NT\MSFax\SentItems", 2, "D:PAI(A;OICI;FA;;;BA)(A;OICI;FA;;;NS)"
  66. "%Common_AppData%\Microsoft\Windows NT\MSFax\Queue", 2, "D:PAI(A;OICI;FA;;;BA)(A;OICI;FA;;;NS)"
  67. "%Common_AppData%\Microsoft\Windows NT\MSFax\ActivityLog", 2, "D:PAI(A;OICI;FA;;;BA)(A;OICI;FA;;;NS)"
  68. "%Common_AppData%\Microsoft\Windows NT\MSFax\Common Coverpages", 2, "D:PAI(A;OICI;FA;;;BA)(A;OICI;0x1200a9;;;WD)"
  69. "%Common_AppData%\Microsoft\Windows NT\NtBackup", 2, "D:P(A;OICI;FA;;;BA)(A;OICI;FA;;;BO)"
  70. ;
  71. ; !!!Note: This is based on the info given by the team, not compared to clean install yet, but this is everyone full control!
  72. ;
  73. "%Common_AppData%\Microsoft\Firewall Client", 2, "D:P(A;OICI;FA;;;WD)"
  74. ;
  75. ; !!!Note: This is based on the info given by the team, but the clean install has different ACL on this folder!
  76. ;
  77. "%Common_AppData%\Microsoft\HTML Help", 2, %Default_Inherited%
  78. [Strings]
  79. ;
  80. ; Default ACL for All Users and AppData\Microsoft, doesn't need to be localized
  81. Default_AllUsers = "D:P(A;OICI;FA;;;SY)(A;OICI;FA;;;BA)(A;OICI;GXGR;;;BU)(A;OICI;0x1301ff;;;PU)(A;OICI;GXGR;;;WD)"
  82. ;
  83. ; Default inherited ACL from about Default_AllUsers, all aces are same, only added an "ID" flag, doesn't need to be localized
  84. ;
  85. Default_Inherited = "D:(A;OICIID;GA;;;SY)(A;OICIID;GA;;;BA)(A;OICIID;0x1301ff;;;PU)(A;OICIID;GXGR;;;BU)(A;OICIID;GXGR;;;WD)"