File/Directory Permission Setting in Windows 2k/2003 Security Template



Hi,
Is there any listing or table to explain all the abbreviations which
are used in defining file/directory permissions in windows security
template? I googled quite a bit and cannot find any useful info except
openning the template in mmc to view it from GUI.

For example:(Taken from win2003 security guide template - SSLF-Domain
Controller.inf )

[File Security]
"%systemRoot%\system32\tlntsvr.exe",1,"D:PAR(A;OIIO;FA;;;BA)(A;OIIO;FA;;;SY)"
"%systemRoot%\system32\tftp.exe",1,"D:PAR(A;OIIO;FA;;;BA)(A;OIIO;FA;;;SY)"

Any docs, tutorial or links to explain these permission setting will
be very helpful. Thanks.

regards,
Rick

---------------------------------------------------------------------------
---------------------------------------------------------------------------



Relevant Pages

  • Re: W2K Hardening
    ... Export is available on the Security setting node. ... settings ... the SCE Analysis and Config snapins to define a new template ... Microsoft MVP (Windows Security) ...
    (microsoft.public.win2000.security)
  • Re: security template file import
    ... one of the more "well documented" features of the GPO based security policy. ... modify the security template - ...
    (microsoft.public.win2000.security)
  • Re: Installer and Security
    ... you have to import the template into a security database before you ... I think SECEDIT will also import the template to a database too, ... unless you find and run the ADMINPAK.MSI file to install the extra MMCs]. ...
    (microsoft.public.win2000.security)
  • Re: IAS - Security template for WAP, PEAP
    ... > I changed my security template, and lost the ability for my wireless ... > Is there an example template somewhere of what security settings need ... Windows Settings, rt-click Security Settings, and choose to import. ...
    (microsoft.public.windows.server.networking)
  • Re: Windows Server 2003 Security Guide issue
    ... security options. ... setup security.inf template as the comparison template and then view ... > I've noted the same beaviour even if I attempt to connect from the DC1 ... > machine to any other client joined to domain (and not only to standalone ...
    (microsoft.public.win2000.security)