Skip to content

v2.4_validate

@selvanair selvanair tagged this 07 Jan 17:50
Currently the username unqualified by the domain is used to validate
a user which fails for domain users. Instead compare the user's SID
with SIDs in the Administrtaors group and ovpn_admin_group.

This has the advantage that connection to a domain controller is not
required and will work even when user has logged in with cached credentials.

Limitations:
(i) Group membership is not checked recursively
(ii) Domain administrators will not be recognized as members of local
Administrtaors group.

Signed-off-by: Selva Nair <selva.nair@gmail.com>
Assets 2
Loading