relay clients: the task's account domain is the machine name on a workgroup box
Over ssh on a workgroup box USERDOMAIN reads WORKGROUP and schtasks refuses the task's UserId with "No mapping between account names and security IDs" (the Windows canary VM, 9 October 2026). The machine name is used there, and whenever the domain\user pair does not translate to a SID. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
79b80c891f
commit
ee98e45302
1 changed files with 5 additions and 1 deletions
|
|
@ -53,7 +53,11 @@ foreach ($f in @('IgneumRelayService.xml', 'igneum-agent-service.ps1', 'igneum-a
|
|||
}
|
||||
$level = 'LeastPrivilege'
|
||||
if ($Highest) { $level = 'HighestAvailable' }
|
||||
$user = $env:USERDOMAIN + '\' + $env:USERNAME
|
||||
# a workgroup box reached over ssh reports USERDOMAIN as WORKGROUP, which schtasks cannot map to a SID (the Windows canary VM,
|
||||
# 9 October 2026: "No mapping between account names and security IDs"); the machine name is the account's domain there
|
||||
$dom = $env:USERDOMAIN
|
||||
if (-not $dom -or $dom -eq 'WORKGROUP' -or $dom -eq $env:COMPUTERNAME) { $dom = $env:COMPUTERNAME } else { try { $null = [Security.Principal.NTAccount]::new($dom, $env:USERNAME).Translate([Security.Principal.SecurityIdentifier]) } catch { $dom = $env:COMPUTERNAME } }
|
||||
$user = $dom + '\' + $env:USERNAME
|
||||
$xml = Get-Content (Join-Path $Here 'IgneumRelayService.xml') -Raw
|
||||
$xml = $xml.Replace('__USER__', $user).Replace('__AGENT_DIR__', $Here).Replace('__RUNLEVEL__', $level)
|
||||
$tmp = Join-Path $env:TEMP ('IgneumRelayService-' + [guid]::NewGuid().ToString('n') + '.xml')
|
||||
|
|
|
|||
Loading…
Reference in a new issue