secedit not working

From: chris (chris@silentcooperative.com)
Date: 09/01/02


From: "chris" <chris@silentcooperative.com>
Date: Sat, 31 Aug 2002 15:56:46 -0700


I have followed the instructions at:
http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/prodtechnol/ad/Windows2000/maintain/opsguide/P
art2/ADOGdApB.asp

..for setting the new security policy on sysvol and no
matter how I specify the paths set in the .inf file it
ALWAYS tells me that the Data Is Invalid.

I'm going nuts here. Did it successfully on a test box
last night and did it the same way today on the production
box and it doesn't let me apply it.

Here's the inf file:
[Unicode]
Unicode=yes
[Version]
signature="$CHICAGO$"
Revision=1
[Profile Description]
Description=default perms for sysvol
[File Security]
;"c:\newsysvoldir\SYSVOL",0,"D:AR(A;OICI;FA;;;BA)"
"%Sysvol%",2,"D:P(A;CIOI;GRGX;;;AU)(A;CIOI;GRGX;;;SO)
(A;CIOI;GA;;;BA)
(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)"
"%Sysvol%\domain\policies",2,"D:P(A;CIOI;GRGX;;;AU)
(A;CIOI;GRGX;;;SO)
(A;CIOI;GA;;;BA)(A;CIOI;GA;;;SY)(A;CIOI;GA;;;CO)
(A;CIOI;GRGWGXSD;;;PA
)"

I've set a new system environment variable "sysvol" to the
value "c:\newsysvoldir\sysvol\sysvol" as it says that you
HAVE TO use the sysvol dir WITHIN sysvol.

Here's the command:
SECEDIT /Configure /cfg sectemplatepath\sysvol.inf /db
sectemplatepath\sysvol.db /overwrite

Anyone have any bright ideas? thanks!

chris
.



Relevant Pages

  • secedit question
    ... for setting the new security policy on sysvol and no ... matter how I specify the paths set in the .inf file it ...
    (microsoft.public.win2000.security)
  • secedit not working
    ... for setting the new security policy on sysvol and no ... matter how I specify the paths set in the .inf file it ...
    (microsoft.public.win2000.security)
  • Re: Applying Security Policy for 20 minutes
    ... I think there might be a problem locating the security policy it tries to ... or partial corruption of SYSVOL. ... > in the event viewer except the normal boot info. ... Does W2K have a boot log? ...
    (microsoft.public.win2000.security)