Security functions
The security functions set, revoke and deny permissions for a user or group (a trustee) on files, directories, shares, services and registry keys. They use two command-line tools, which must be available on the client when the package runs.
Files, directories, shares and services: SubInACL.exe
Section titled “Files, directories, shares and services: SubInACL.exe”The file, directory, share and service functions use SubInACL.exe, a Microsoft command-line tool. SubInACL.exe isn’t installed with the CapaInstaller client. You can download the installer here: subinacl.msi. To make sure the tool is available, add subinacl.exe to the Kit folder of the package.
The CapaInstaller Scripting Library looks for SubInACL.exe in these locations, in this order:
- The
Utilfolder in the CapaInstaller client folder, for exampleC:\Program Files\CapaInstaller\Client\Util Windows Resource Kits\Toolsin the Program Files folder. On 64-bit Windows, the library looks inProgram Files (x86). This is wheresubinacl.msiinstalls the tool.- The Windows system folder,
%WinDir%\System32 - The root folder of the package (
gsPackageRoot) - The
Kitfolder of the package, for example\\<Management Server>\<Share name>\ComputerJobs\<PackageName>\<Version>\Kit
If SubInACL.exe isn’t found, the package log shows SubInAcl.exe not found locally or as part of package, and the function returns False.
SubInACL writes its errors to SetSecurity_Error.log in the CapaInstaller log folder. If the file contains any text after the command, the library copies the text to the package log and the function returns False.
Registry keys: SetACL.exe
Section titled “Registry keys: SetACL.exe”SubInACL.exe doesn’t support the 64-bit registry, and 32-bit processes on 64-bit Windows are redirected to the 32-bit registry. The registry functions therefore use SetACL.exe instead. The CapaInstaller client includes SetACL.exe in its Util folder, as SetACL_x64.exe and SetACL_x86.exe. The library uses the version that matches the execution environment of the script. If the file isn’t in the Util folder, the library looks in the Kit folder of the package.
In this section
Section titled “In this section”- Security_DenyDirAccess
- Security_DenyFileAccess
- Security_DenyRegAccess
- Security_DenyServiceAccess
- Security_DenyShareAccess
- Security_RevokeDirPermissions
- Security_RevokeFilePermissions
- Security_RevokeRegPermissions
- Security_RevokeServicePermissions
- Security_RevokeSharePermissions
- Security_SetDirPermissions
- Security_SetFilePermissions
- Security_SetRegPermissions
- Security_SetServicePermissions
- Security_SetSharePermissions