relay clients: the task's account domain is the machine name on a workgroup box

Over ssh on a workgroup box USERDOMAIN reads WORKGROUP and schtasks refuses the task's UserId with "No mapping between
account names and security IDs" (the Windows canary VM, 9 October 2026). The machine name is used there, and whenever
the domain\user pair does not translate to a SID.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
igneum-labs 2026-10-09 09:49:11 +00:00
parent 79b80c891f
commit ee98e45302

View file

@ -53,7 +53,11 @@ foreach ($f in @('IgneumRelayService.xml', 'igneum-agent-service.ps1', 'igneum-a
}
$level = 'LeastPrivilege'
if ($Highest) { $level = 'HighestAvailable' }
$user = $env:USERDOMAIN + '\' + $env:USERNAME
# a workgroup box reached over ssh reports USERDOMAIN as WORKGROUP, which schtasks cannot map to a SID (the Windows canary VM,
# 9 October 2026: "No mapping between account names and security IDs"); the machine name is the account's domain there
$dom = $env:USERDOMAIN
if (-not $dom -or $dom -eq 'WORKGROUP' -or $dom -eq $env:COMPUTERNAME) { $dom = $env:COMPUTERNAME } else { try { $null = [Security.Principal.NTAccount]::new($dom, $env:USERNAME).Translate([Security.Principal.SecurityIdentifier]) } catch { $dom = $env:COMPUTERNAME } }
$user = $dom + '\' + $env:USERNAME
$xml = Get-Content (Join-Path $Here 'IgneumRelayService.xml') -Raw
$xml = $xml.Replace('__USER__', $user).Replace('__AGENT_DIR__', $Here).Replace('__RUNLEVEL__', $level)
$tmp = Join-Path $env:TEMP ('IgneumRelayService-' + [guid]::NewGuid().ToString('n') + '.xml')