Source code of Windows XP (NT5)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

209 lines
6.0 KiB

  1. ; * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
  2. ;
  3. ; Registry ACL definition file
  4. ;
  5. ; Use this file to set the registry key ACL's to the desired
  6. ; security. The format of each entry is:
  7. ;
  8. ; [RegistryKey]
  9. ; Domain\Account = [INHERIT,] access [, access]...
  10. ;
  11. ; where:
  12. ;
  13. ; RegistryKey is the key path of the key to set. This is in the
  14. ; format of:
  15. ;
  16. ; PREDEFINED_KEY\[path | *]
  17. ; where:
  18. ;
  19. ; PREDEFINED_KEY is one of:
  20. ; HKEY_LOCAL_MACHINE
  21. ; HKEY_USERS
  22. ; HKEY_CURRENT_USER
  23. ; HKEY_CLASSES_ROOT
  24. ;
  25. ; and
  26. ; path is the path to the key. The path may end in a "*"
  27. ; character in which case, all sub-keys of the specified
  28. ; path will be set to the specified security
  29. ;
  30. ; for example:
  31. ;
  32. ; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\*]
  33. ;
  34. ; would assign the security description of that section
  35. ; to all keys UNDER the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
  36. ; key but NOT to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft
  37. ; key itself. To assign security to that key, an entry
  38. ; such as the following would be needed:
  39. ;
  40. ; [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft]
  41. ;
  42. ;
  43. ; Domain\Account
  44. ; specifies the account to recieve the specified access for that
  45. ; key. Account may be an account or a group. For Example to give
  46. ; permissions to all administrator accounts, the:
  47. ;
  48. ; BUILTIN\Administrators
  49. ;
  50. ; would be the correct entry.
  51. ;
  52. ; access is defined as one of the following:
  53. ;
  54. ; QV = Query Value
  55. ; SV = Set Value
  56. ; CS = Create Subkey
  57. ; ES = Enumerate Subkeys
  58. ; NT = Notify
  59. ; CL = Create Link
  60. ;
  61. ; DE = Delete
  62. ; RC = Read Control
  63. ; WD = Write DAC
  64. ; WO = Write Owner
  65. ;
  66. ; there are also some predefined combination access keys:
  67. ;
  68. ; NONE = no access
  69. ; FULL = QV, SV, CS, ES, NT, CL, DE, WD, WO, RC
  70. ; READ = QV, ES, NT, RC
  71. ;
  72. ; The 'INHERIT' string can be specified (in the first entry only)
  73. ; to indicate this is the access control to be assigned by default
  74. ; to created subkeys.
  75. ;
  76. ; * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
  77. [HKEY_LOCAL_MACHINE\SOFTWARE]
  78. BUILTIN\Administrators = FULL
  79. BUILTIN\Administrators = INHERIT, FULL
  80. CREATOR OWNER = FULL
  81. CREATOR OWNER = INHERIT, FULL
  82. SYSTEM = FULL
  83. SYSTEM = INHERIT, FULL
  84. Everyone = QV, SV, CS, ES, NT, DE, RC
  85. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  86. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes]
  87. BUILTIN\Administrators = FULL
  88. BUILTIN\Administrators = INHERIT, FULL
  89. CREATOR OWNER = FULL
  90. CREATOR OWNER = INHERIT, FULL
  91. SYSTEM = FULL
  92. SYSTEM = INHERIT, FULL
  93. Everyone = QV, SV, CS, ES, NT, DE, RC
  94. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  95. [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*]
  96. BUILTIN\Administrators = FULL
  97. BUILTIN\Administrators = INHERIT, FULL
  98. SYSTEM = FULL
  99. SYSTEM = INHERIT, FULL
  100. CREATOR OWNER = FULL
  101. CREATOR OWNER = INHERIT, FULL
  102. Everyone = QV, SV, CS, ES, NT, DE, RC
  103. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  104. [HKEY_LOCAL_MACHINE\SOFTWARE\Description]
  105. BUILTIN\Administrators = FULL
  106. BUILTIN\Administrators = INHERIT, FULL
  107. SYSTEM = FULL
  108. SYSTEM = INHERIT, FULL
  109. CREATOR OWNER = FULL
  110. CREATOR OWNER = INHERIT, FULL
  111. Everyone = QV, SV, CS, ES, NT, DE, RC
  112. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  113. [HKEY_LOCAL_MACHINE\SOFTWARE\Description\*]
  114. BUILTIN\Administrators = FULL
  115. BUILTIN\Administrators = INHERIT, FULL
  116. SYSTEM = FULL
  117. SYSTEM = INHERIT, FULL
  118. CREATOR OWNER = FULL
  119. CREATOR OWNER = INHERIT, FULL
  120. Everyone = QV, SV, CS, ES, NT, DE, RC
  121. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  122. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft]
  123. BUILTIN\Administrators = FULL
  124. BUILTIN\Administrators = INHERIT, FULL
  125. SYSTEM = FULL
  126. SYSTEM = INHERIT, FULL
  127. CREATOR OWNER = FULL
  128. CREATOR OWNER = INHERIT, FULL
  129. Everyone = QV, SV, CS, ES, NT, DE, RC
  130. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  131. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\*]
  132. BUILTIN\Administrators = FULL
  133. BUILTIN\Administrators = INHERIT, FULL
  134. SYSTEM = FULL
  135. SYSTEM = INHERIT, FULL
  136. CREATOR OWNER = FULL
  137. CREATOR OWNER = INHERIT, FULL
  138. Everyone = QV, SV, CS, ES, NT, DE, RC
  139. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  140. [HKEY_LOCAL_MACHINE\SOFTWARE\Program Groups]
  141. BUILTIN\Administrators = FULL
  142. BUILTIN\Administrators = INHERIT, FULL
  143. CREATOR OWNER = FULL
  144. CREATOR OWNER = INHERIT, FULL
  145. SYSTEM = FULL
  146. SYSTEM = INHERIT, FULL
  147. BUILTIN\Power Users = QV, SV, CS, ES, NT, DE, RC
  148. BUILTIN\Power Users = INHERIT, QV, SV, CS, ES, NT, DE, RC
  149. Everyone = READ
  150. Everyone = INHERIT, READ
  151. [HKEY_LOCAL_MACHINE\SOFTWARE\Secure]
  152. BUILTIN\Administrators = FULL
  153. BUILTIN\Administrators = INHERIT, FULL
  154. CREATOR OWNER = FULL
  155. CREATOR OWNER = INHERIT, FULL
  156. SYSTEM = FULL
  157. SYSTEM = INHERIT, FULL
  158. Everyone = READ
  159. Everyone = INHERIT, READ
  160. [HKEY_LOCAL_MACHINE\SOFTWARE\Windows 3.1 Migration Status]
  161. BUILTIN\Administrators = FULL
  162. BUILTIN\Administrators = INHERIT, FULL
  163. CREATOR OWNER = FULL
  164. CREATOR OWNER = INHERIT, FULL
  165. SYSTEM = FULL
  166. SYSTEM = INHERIT, FULL
  167. Everyone = READ
  168. Everyone = INHERIT, READ
  169. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server]
  170. BUILTIN\Administrators = FULL
  171. BUILTIN\Administrators = INHERIT, FULL
  172. SYSTEM = FULL
  173. SYSTEM = INHERIT, FULL
  174. CREATOR OWNER = FULL
  175. CREATOR OWNER = INHERIT, FULL
  176. Everyone = QV, SV, CS, ES, NT, DE, RC
  177. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  178. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\*]
  179. BUILTIN\Administrators = FULL
  180. BUILTIN\Administrators = INHERIT, FULL
  181. SYSTEM = FULL
  182. SYSTEM = INHERIT, FULL
  183. CREATOR OWNER = FULL
  184. CREATOR OWNER = INHERIT, FULL
  185. Everyone = QV, SV, CS, ES, NT, DE, RC
  186. Everyone = INHERIT, QV, SV, CS, ES, NT, DE, RC
  187. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server]
  188. BUILTIN\Administrators = FULL
  189. BUILTIN\Administrators = INHERIT, FULL
  190. SYSTEM = FULL
  191. SYSTEM = INHERIT, FULL
  192. CREATOR OWNER = FULL
  193. CREATOR OWNER = INHERIT, FULL
  194. Everyone = READ
  195. Everyone = INHERIT, READ