Skip to content

Security functions

The security functions set, revoke and deny permissions for a user or group (a trustee) on files, directories, shares, services and registry keys. They use two command-line tools, which must be available on the client when the package runs.

Files, directories, shares and services: SubInACL.exe

Section titled “Files, directories, shares and services: SubInACL.exe”

The file, directory, share and service functions use SubInACL.exe, a Microsoft command-line tool. SubInACL.exe isn’t installed with the CapaInstaller client. You can download the installer here: subinacl.msi. To make sure the tool is available, add subinacl.exe to the Kit folder of the package.

The CapaInstaller Scripting Library looks for SubInACL.exe in these locations, in this order:

  1. The Util folder in the CapaInstaller client folder, for example C:\Program Files\CapaInstaller\Client\Util
  2. Windows Resource Kits\Tools in the Program Files folder. On 64-bit Windows, the library looks in Program Files (x86). This is where subinacl.msi installs the tool.
  3. The Windows system folder, %WinDir%\System32
  4. The root folder of the package (gsPackageRoot)
  5. The Kit folder of the package, for example \\<Management Server>\<Share name>\ComputerJobs\<PackageName>\<Version>\Kit

If SubInACL.exe isn’t found, the package log shows SubInAcl.exe not found locally or as part of package, and the function returns False.

SubInACL writes its errors to SetSecurity_Error.log in the CapaInstaller log folder. If the file contains any text after the command, the library copies the text to the package log and the function returns False.

SubInACL.exe doesn’t support the 64-bit registry, and 32-bit processes on 64-bit Windows are redirected to the 32-bit registry. The registry functions therefore use SetACL.exe instead. The CapaInstaller client includes SetACL.exe in its Util folder, as SetACL_x64.exe and SetACL_x86.exe. The library uses the version that matches the execution environment of the script. If the file isn’t in the Util folder, the library looks in the Kit folder of the package.