s4-drs: allow DrsReplicaGetInfo as a DC
authorAndrew Tridgell <tridge@samba.org>
Sat, 27 Nov 2010 12:47:03 +0000 (23:47 +1100)
committerAndrew Tridgell <tridge@samba.org>
Sat, 27 Nov 2010 13:16:38 +0000 (00:16 +1100)
source4/rpc_server/drsuapi/dcesrv_drsuapi.c

index f4dad093354caf9712f3a88778d0cbf274494eee..6829416107b0b55c932450a0569e5bffdd17fadf 100644 (file)
@@ -826,7 +826,7 @@ static WERROR dcesrv_drsuapi_DsReplicaGetInfo(struct dcesrv_call_state *dce_call
        if (!lpcfg_parm_bool(dce_call->conn->dce_ctx->lp_ctx, NULL,
                         "drs", "disable_sec_check", false)) {
                level = security_session_user_level(dce_call->conn->auth_state.session_info, NULL);
-               if (level < SECURITY_ADMINISTRATOR) {
+               if (level < SECURITY_DOMAIN_CONTROLLER) {
                        DEBUG(1,(__location__ ": Administrator access required for DsReplicaGetInfo\n"));
                        security_token_debug(0, 2, dce_call->conn->auth_state.session_info->security_token);
                        return WERR_DS_DRA_ACCESS_DENIED;