Access Control Entries

An access control entry (ACE) is an element in an access control list (ACL). An ACL can have zero or more ACEs. Each ACE controls or monitors access to an object by a specified trustee. For information about adding, removing, or changing the ACEs in an object's ACLs, see Modifying the ACLs of an Object in C++.

(ACE是ACL中的一个元素。一个ACL可以拥有多个ACE,也可以没有一个ACE。每个ACE控制或者监控一个受信成员对受保护对象的访问行为。)

There are six types of ACEs, three of which are supported by all securable objects. The other three types are Object-specific ACEs supported by directory service objects.

(有六种类型ACE,其中三种被所有受保护对象所支持。另外三种类型为特定类型ACE,目录服务对象支持这三种类型。)

All types of ACEs contain the following access control information:

  • A security identifier (SID) that identifies the trustee to which the ACE applies.
  • An access mask that specifies the access rights controlled by the ACE.
  • A flag that indicates the type of ACE.
  • A set of bit flags that determine whether child containers or objects can inherit the ACE from the primary object to which the ACL is attached

    (所有类型的ACE由以下访问控制信息组成:

    1.一个指明应用于哪个ACE的受信成员的安全标识符SID

    2.由ACE控制的指定访问权限的访问掩码

    3.指明ACE类型的标志位

    4.决定子容器或者子对象是否能够从附属的ACL的首要对象继承ACE的一系列比特标志位)

    三种支持所有保护对象的ACE类型为


    1.Access-denied ACE:Used in a discretionary access control list (DACL) to deny access rights to a trustee.
    拒绝访问ACE:在DACL中用于拒绝受信对象的访问
    2.Access-allowed ACE:Used in a DACL to allow access rights to a trustee.
    允许访问ACE:在DACL中用于允许受信对象的访问
    3.System-audit ACE:Used in a system access control list (SACL) to generate an audit record when the trustee attempts to exercise the specified access rights.
    系统审计ACE:在SACL中,当受信对象试图测试指定的访问权限时,生成一条审计记录


    我把trustee翻译成受信对象,msdn的解释为“A trustee is the user account, group account, or logon session to which an access control entry (ACE) applies.”我的理解是trustee是ACE中的用户账户、组账户或者登陆会话

转载于:https://www.cnblogs.com/debug-me/p/6793190.html

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值