
ãããããããªãã®ä»äºã§ã¯ãç§ã®ããã«ã誰ãã©ã®ããã«ãµãŒãã¹ãæäŸããããæç¢ºã§ã¯ãªãäŒæ¥ã®ITã·ã¹ãã ã«å¯ŸåŠããå¿
èŠããããŸãã äŒç€Ÿãå®å
šã«çšŒåãããåã«ãITç£æ»ãè¡ãããã¹ãŠã®ã·ã¹ãã ãæŽé ããããšãäžå¯æ¬ ã§ãã
å€ãã®å Žåãæ³šæããªãã·ã¹ãã ã®1ã€ã¯1Cã·ã¹ãã ã§ãã ããšãã°ããã©ã«ããŒåã
ãnew_copybase1_oldããŸãã¯
ãBase1KompaniyaZPãã§ããããŒã¿ããŒã¹ããŸãã¯äºãã«å
¥ãåã«ãªã£ããã©ã«ããŒãèŠã€ããããšãã§ããŸãã
ãããã®ããŒã¿ããŒã¹ã«èª°ãäœãã¢ã¯ã»ã¹ã§ããã®ãã倿ããã®ã¯éåžžã«é£ããå ŽåããããŸãã 1Cã¢ããªã±ãŒã·ã§ã³èªäœã®ã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒäžã®ããŒã¿ããŒã¹ã®ãªã¹ãã«ã¯ããããã«ããååãä»ããããšãã§ããŸãã äžè¬çã«ãããŸã幞ããªåçã§ã¯ãããŸããã
ãã¹ãŠã®ããŒã¿ããŒã¹ã1ã€ã®å
±éæšæºã«ãŸãšãããŠãŒã¶ãŒã®æ¥ç¶ãèªååãããšããæ¥ãããç«ããé¡ãããŸãã
ãã¹ãŠã®ããŒã¹ãå
±éã®åºæºã«åãããç©äºãæŽçããŸã-ããã¯ãã¹ãŠè¯ãããšã§ãïŒ ããããæãè¿
éãã€å¹ççã«ãããè¡ãæ¹æ³ã¯ïŒ
解決çãèŠã€ãã
Webã§æ€çŽ¢ãããšããããã®ãããã¯ã«é¢ããæé«ã®èšäºãHabréã«ããããšãããããŸããã
1.
ãããŒã¿ããŒã¹ãªã¹ã1C 8.2ã®ç®¡çã ;
2.
ãäœçŸãã®1CããŒã¹ã調çããçããªãæ¹æ³ã3.
ãActive Directoryã䜿çšãã1C 8.2ããŒã¿ããŒã¹ã®ãªã¹ãã®ç®¡çã ;
4.
ã1CããŒã¿ããŒã¹ãªã¹ãã®ç°¡åãªç®¡ç ã
ãSergey-S-Kovalevã«ããèšäº
ã1CããŒã¿ããŒã¹ãªã¹ãã®ç°¡åãªç®¡çãã¯æãæçšã§ãããšæãããæåãªåŒçšããå§ãŸããŸãã
ã1æ¥ã倱ã£ãŠãã5åã§é£ã¶æ¹ãè¯ããïŒcïŒm / f翌ãèãå°Ÿã
ãããããã¹ãŠãããã»ã©éããŠç°¡åã§ã¯ãããŸããã
ãã®ããã
Sergey-S-KovalevãŠãŒã¶ãŒã®èšäºã«åŸã£ãŠã»ããã¢ãããè¡ãã«ã¯ã6ã€ã®æ®µéã«åãããæé ã«åŸãå¿
èŠããããŸãã
ã¹ããŒãž1-ã€ã³ãã³ããªã
ã¹ããŒãž2-1Cã®ADã°ã«ãŒãã
ã¹ããŒãž3-1Cæ§æãã¡ã€ã«ã
ã¹ããŒãž4-ãã¡ã€ã«ãŸãã¯DFSãªãœãŒã¹ã
ã¹ããŒãž5-ã°ã«ãŒãããªã·ãŒã
ã¹ããŒãž6-ãŠãŒã¶ãŒã
æé 1ã5ã®æé ã¯ãåäŒæ¥ã«å¯ŸããŠ1åãã€å®è¡ãããŸãããããã«ã¯ã«ãŒãã³ã¯ãããŸãããæã§ç°¡åã«å®è¡ã§ããŸãã
Sergey-S-KovalevãæäŸããã»ããã¢ããã¹ããŒã ã¯çŽ æŽãããã§ãïŒ ã¹ã¯ãªããã¯ãããŸããããã¹ãŠãç°¡åãã€æç¢ºã«æ©èœããŸãã ãããã1æ¥ã§ã¯ãªãããã®äœæ¥ã¹ããŒã ãã»ããã¢ããããå¿
èŠãããå Žåãããšãã°ãåèšã§çŽ200ã®1CããŒã¹ãæã€ããšãã§ãã10瀟ã§å€±ãå¿
èŠããããŸãã
ã€ãŸããå€§äŒæ¥ã§ã®åæã»ããã¢ããã¯éåžžã«é·ãéå±ãªãã®ã«ãªããŸãã
ã¹ãããã®äžéšãèªååããã¹ãããæ°ãæžããããšããå§ãããŸãã
ç§ã話ããŠããããšãããããçè§£ããããã«ããŸããç°¡åãª1CããŒã¿ããŒã¹ç®¡çããèªãããšããå§ãããŸã ã
ã¹ããŒãž1-ã€ã³ãã³ããª
1.å³ã«ç€ºãããã«ãå
±éã®äŒèšãªãœãŒã¹ã«Excelãã¡ã€ã«ãäœæããŸãã

ãã®ãã¡ã€ã«ã«å€ãããŒã¿ããŒã¹ãšãã©ã«ããŒã®ååãå¿
ã远å ããŠãåŸã§ããŒã¿ããŒã¹ã®ã³ããŒå
ãæç¢ºã«ããŠãã ããã
OldBaseNameãOldFolderName ã ãã¡ã€ã«ã¯
ããã§ååŸã§ã
ãŸã ã
2.äŒç€Ÿã®æãéèŠãªäŒèšå£«ãšäžç·ã«ããã£ãŒã«ãã«å
¥åããŸãã
BaseName, FolderName, GroupName, AccessUser(1-7)
BaseName
åã¯ãIP-Ivanov_BUKHãªã©ã®æšæºã«åŸã£ãŠãã·ã¢èªã§æåã§å
¥åãããŸããFolderName
åã«ã¯ãæšæºïŒãã®å Žåã¯IP-IVANOV_BUHïŒã«åŸã£ãŠã©ãã³ã¢ã«ãã¡ããããæåã§å
¥åãããŸãã- ADã°ã«ãŒãã®ååã¯ã
FolderName
åã«åºã¥ããŠæ¢ã«çæãããŠãFolderName
ãã®äŸã§ã¯GRRS_IP-IVANOV_BUHã§ããExcelã§ã¯ãä»ã®ã»ã«ã®æ
å ±ã«åºã¥ããŠã»ã«ã®å
容ãè£å®ããæ¹æ³ãç¥ã£ãŠãããšæããŸãã - AccessUserã¯ãæãéèŠãªäŒèšå£«èªèº«ã«å°ããããšã§ã¢ã¯ã»ã¹ã§ããŸãããäœæ¥ã容æã«ããããšãã§ããŸãã ãããè¡ãã«ã¯ãããšãã°æ¬¡ã®ã³ãã³ãã䜿çšããŠãADããã¢ã«ãŠã³ãã£ã³ã°ã¬ã³ãŒãã®ãªã¹ããååŸããŸã
Get-Aduser -searchbase "OU=Accountants, DC=domain, DC=ru" -filter * -Properties SamAccountname | FT SamAccountname
ãã®ãªã¹ãããã¡ã€ã«ã®2çªç®ã®ã·ãŒãã«é
眮ããŸãã - AccessUserãã£ãŒã«ãã®æšªã«ããã®ãªã¹ãããã€ã³ãããå¿
èŠããããŸãã æ¹æ³ãããããªãå Žåã¯ããExcelã»ã«ã«ããããããŠã³ãªã¹ãã远å ããæ¹æ³ããªã©ãGoogleã«å°ãããããã¡ã€ã«ã䜿çšããŠãã ããã
ãã®çµæãæãéèŠãªäŒèšå£«ã¯ããªã¹ããããŠãŒã¶ãŒãéžæããŠãåããŒã¿ããŒã¹ãžã®ã¢ã¯ã»ã¹ãåçŽã«ä»å ããŸãã ãªã¹ãã¯ãExcelèªäœã®ããŒã«ã䜿çšããŠäºåã«äžŠã¹æ¿ããããšãã§ããŸããããšãã°ãæãé »ç¹ã«äœ¿çšãããã¢ã«ãŠã³ããæåã«é
眮ããŸãã
3.ãã®ãã¡ã€ã«ã«å
¥åããåŸããã¡ã€ã«ãä¿åããã¹ã¯ãªãããèµ·åãããã£ã¬ã¯ããªã«ã³ããŒããå¿
èŠããããŸãã
Sergey-S-Kovalevãã¡ã€ã«ãšã¯ç°ãªãããŠãŒã¶ãŒãããã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã説æããµãŒããŒãšã¯ã©ã¹ã¿ãŒã®ååããããŸããã ç§ã®ç°å¢ã§ã¯ããã®æ
å ±ã¯äžèŠã§ããããã¡ã€ã«ã«å«ããŸããã§ããã
ã¹ããŒãž2-ã¹ã¯ãªããã®å®è¡
ãããããæåã®æ®µéã®çµæãšããŠå€æãããã¡ã€ã«ãã¹ã¯ãªããã«ãã£ãŒãããããšãæ¢ã«ãåãã§ãããã ã¹ã¯ãªããã¯ã
Sergey-S-Kovalevãã¹ããã2ã3ã4ã6ã§èª¬æãããã¹ãŠã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸãã
ã¹ã¯ãªããã¯äœãããŸããïŒ
1.åããŒã¹ã®ã°ã«ãŒããADã«äœæããŸãã
2.åã°ã«ãŒãã®èª¬æãã£ãŒã«ãã«ããŒã¹ãæã€ãã©ã«ããŒãžã®ãã¹ã远å ããŸãã
3.åã°ã«ãŒãã®ãã¡ã¢ããã£ãŒã«ãã«ãããŒã¿ããŒã¹ã®ååãšããŒã¿ããŒã¹ã®ãããã©ã«ããŒãžã®ãã¹ã远å ããŸãã
4.ãªã¹ãã«åŸã£ãŠãŠãŒã¶ãŒã¢ã¯ã»ã¹ã°ã«ãŒãã«è¿œå ããŸãã
5.ãã¹ãŠã®ããŒã¿ããŒã¹ã®ãªã¹ããå«ãå
±éãã¡ã€ã«1CEStart.cfgãçæãããã®ãã¡ã€ã«ã1Cæ§æãã¡ã€ã«ãšãšãã«ãããã¯ãŒã¯ãã©ã«ããŒã«é
眮ããŸãã
6.åããŒã¿ããŒã¹ã®v8iãã¡ã€ã«ãçæãããããã®ãã¡ã€ã«ã1Cæ§æãã¡ã€ã«ã®ãããããã¯ãŒã¯ãã©ã«ããŒã«é
眮ããŸãã
7.ã¢ã¯ã»ã¹ãªã¹ãã®åv8iãã¡ã€ã«ã«å¯Ÿå¿ããã°ã«ãŒããèŠå®ããŸãã
8.ããŒã¿ããŒã¹çšã®ãã©ã«ããäœæãããã©ã«ãã®ã¢ã¯ã»ã¹ãªã¹ãã«å¯Ÿå¿ããã°ã«ãŒããæžã蟌ã¿ãŸãã
äžè¬ã«ãã¹ã¯ãªããã¯ã
Sergey-S-Kovalevãèšäºã§æäœæ¥ã§è¡ã£ãã»ãŒãã¹ãŠã®ããšãè¡ããŸãã
ã¹ã¯ãªãããå®è¡ããåã«ã以äžãå¿
èŠã§ãã
ïŒãããã®ã¢ã¯ã·ã§ã³ã®èªååã¯ããããŸã§ã®èšç»ã«ã®ã¿å«ãŸããŠããŸãïŒADã°ã«ãŒããäœæãã
1.ãã¡ã€ã³ã«OUãäœæããŠã1CããŒã¿ããŒã¹ãžã®ã¢ã¯ã»ã¹æš©ãæã€ã°ã«ãŒããä¿åããŸãã ç§ã®äŸã§ã¯ã$ OU =â OU = 1CãOU = ResourcesãDC = domainãDC = ruâã«ãªããŸã
2.ãã®OUã«ã°ã«ãŒãGRRS_1C_ConfigBasesROãäœæããŸãã ã°ã«ãŒããDomain computersããã°ã«ãŒãGRRS_1C_ConfigBasesROã«è¿œå ããŸã
3.ãã®OUã«ã°ã«ãŒãGRRS_1CBasesãäœæããŸãã
4.ãã®OUã«GRUS_1Cadminsã°ã«ãŒããäœæãã1C管çè
ã远å ããŸãïŒãªãã·ã§ã³ïŒ
ãã©ã«ããŒãäœæãã
1. 1CãµãŒããŒäžã«ããŒã¿ããŒã¹ãä¿åããããã®ãã©ã«ããŒãäœæããŸãã ç§ãã¡ã®å Žåã¯1cshareã«ãªããŸã
2. [å
±æ]ã¿ãã®æš©éã§èšé²ããããã«ãGRRS_1CBasesã°ã«ãŒãã«1cshareãã©ã«ããŒãžã®ã¢ã¯ã»ã¹ãèš±å¯ããå¿
èŠããããŸãã
3. [ã»ãã¥ãªãã£]ã¿ãã§ããŠãŒã¶ãŒã°ã«ãŒããåé€ããGRRS_1CBasesã°ã«ãŒãã®èªã¿åãæš©éãç»é²ããŸãã
4.ãã¡ã€ã³å
ã®å
±æDFSãã©ã«ããŒãŸãã¯ãã©ã«ããŒã®ã¿ãäœæããŸãïŒäŸïŒ\\ domain.ru \ DfsShare \ 1cconfig \ïŒ
5.ãã®ãã©ã«ããŒã«1Cæ§æãã¡ã€ã«ããããŸãã
6.ãã©ã«ã\\ domain.ru \ DfsShare \ 1cconfig \ã«ãã°ã«ãŒãGRRS_1C_ConfigBasesROã®èªã¿åãå°çšã¢ã¯ã»ã¹æš©ãä»äžããŸãã
ã¹ã¯ãªãããèµ·åãããŠãŒã¶ãŒã¯ãããŒã¿ããŒã¹ã®ãããã©ã«ããŒããã³\\ domain.ru \ DfsShare \ 1cconfig \ãã©ã«ããŒãžã®æžã蟌ã¿ã¢ã¯ã»ã¹æš©ãæã£ãŠããå¿
èŠããããŸãã
ã¹ã¯ãªããèµ·åèŠä»¶
ãã®ã¹ã¯ãªããã¯ãMicrosoft Access Database Engine 2010 Redistributableã䜿çšããŠExcelãã¡ã€ã«ãèªã¿åãããšãå®è£
ããŠããŸã
ã¹ã¯ãªãããèµ·åãããµãŒããŒã«ãã®è£œåãããã«ã€ã³ã¹ããŒã«ããããšããå§ãããŸãã
ãšã³ãžã³ã¯
ããããããŠã³ããŒãã§ã
ãŸã ã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãããæ·±åºŠããšã³ãžã³ã®ãããæ·±åºŠãšäžèŽããããšãéèŠã§ãã
泚æïŒ åäœäžã®ã¯ã©ã€ã¢ã³ãã³ã³ãã¥ãŒã¿ãŒããã¹ã¯ãªãããå®è¡ããå ŽåãMicrosoft Officeã®ãããæ·±åºŠããšã³ãžã³ã®ãããå¹
ãšäžèŽããå¿
èŠããããŸãã
ãµãŒããŒã«ãšã³ãžã³ãã€ã³ã¹ããŒã«ããããšããå§ãããŸããã³ã³ãã¥ãŒã¿ãŒã«Microsoft Officeãåã€ã³ã¹ããŒã«ããå¿é
ã¯ãããŸããã ã¹ã¯ãªãããå®è¡ããã«ã¯ãPowerShellããŒãžã§ã³4.0以éãšPowerShellã¢ãžã¥ãŒã«ãåããADã¹ãããã€ã³ãã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ããå¿
èŠããããŸãã
ãŸããæ¬¡ã®å€æ°ãã¹ã¯ãªããã«ç»é²ããå¿
èŠããããŸãã# 1-,
$1CServer = "nn-1cserver"
# , 1.
$ShareName = "1cshare"
#OU Active Directory, 1c
$OU = âOU=1C, OU=Resources, DC=domain, DC=ruâ
# DFS , 1
$1CConfigFolder = "\\domain.ru\DfsShare\1cconfig\"
# ,
$datafile = "BasesBuh.xlsx"
#
$strSheetName = 'Sheet1$'
æ³šïŒ csvã§ã¯ãªãExcelã®èªã¿åããå®è£
ããã®ã¯ãªãã§ããïŒ ããªã«æåã®ãšã³ã³ãŒãã芳å¯ããå¿
èŠããããããCSVã䜿çšããã®ã¯å¥œãã§ã¯ãããŸããããŸããCSVã¯ç·šéã«äžäŸ¿ã§ãã Excelãã¡ã€ã«ãèªã¿åããå Žåã¯ããã®åœ¢åŒãæºåããã«ããã«ã¹ã¯ãªããã«ã¹ãªããã§ããŸãã
ã¹ããŒãž3-ãŠãŒã¶ãŒçšã®ããªã·ãŒã®äœæ
Sergey-S-Kovalevã¯ããã®ã¹ããŒã ã®éçšã«é¢ããããªã·ãŒã®äœæã«ã€ããŠéåžžã«ãã説æããŠããŸãã
1.圌ã®èšäºã®äžã§ãæ§æãã¡ã€ã«1CEStart.cfgãå
±æãããã¯ãŒã¯ãã©ã«ããŒããã³ã³ãã¥ãŒã¿ãŒã®ãã©ã«ããŒã«ã³ããŒããŸãïŒ
ProgramDataïŒ
\ 1C \ 1CEStart \ãã®ã³ã³ãã¥ãŒã¿ãŒã®ããªã·ãŒãäœæããŸãã
2.ããã«ãããªã·ãŒã§ã¯ãåãŠãŒã¶ãŒã®ïŒ
AppdataïŒ
\ 1C \ 1CEStart \ ibases.v8iãã¡ã€ã«ã確å®ã«æ¶å»ããå¿
èŠããããŸãã æ°ããã³ã³ãã³ãã¯ã1Cã®æåã®èµ·åæã«1CEStart.cfgãã¡ã€ã«ãã圢æãããŸãã
ã¹ããŒãž4-å€ãããŒã¿ããŒã¹ãæ°ãããã©ã«ããŒã«ã³ããŒãã
ã¹ã¯ãªãããå®è¡ãããã¹ãŠã®ã°ã«ãŒãããã©ã«ããŒãããã³ãã¡ã€ã«ãäœæããããå€ãããŒã¿ããŒã¹ãæ°ããå Žæã«ã³ããŒããå¿
èŠããããŸããã€ãŸããæ°ãããã©ã«ããŒã«ããããé
åžããŸãã
ããã§ã¯
ãOldFolderNameãFolderNameã®åã圹ç«ã¡ãŸã
ãããã«ã¹ã¯ãªãã###########################################################
# AUTHOR : Rinat K. Nugaev - http://www.nugaev.net - rinat@nugaev.net
# DATE : 07-02-2016
# EDIT : 07-03-2016
# COMMENT : This script creates folders, groups, and other
# stuff for 1C envinronment.
# Use it for your own risk!
# VERSION : 1.2
###########################################################
# CHANGELOG
# Version 1.2: 07-03-2016 - Changed the code
# - Added DataFilePath checking
# - Added AD modules installing
# - Changed users's array creating
# - Added Russian comments
# AD PowerShell
Try
{
Import-Module ActiveDirectory -ErrorAction Stop
}
Catch
{
Write-Host "[ERROR]`t ActiveDirectory Powershell ! , !"
Write-Host "[ERROR]`t Windows 2008/2008R2 Import-Module ServerManager"
Write-Host "[ERROR]`t Add-WindowsFeature RSAT-AD-PowerShell"
Write-Host "[ERROR]`t Windows 2012/2012R2 Add-WindowsFeature RSAT-AD-PowerShell"
Exit 1
}
#---------------------------------------------------------------------------------------
# -
#---------------------------------------------------------------------------------------
#
$dataFile = "BasesBuh.xlsx"
# 1-,
$1Cserver = "nn-1cserver"
# 1 , 1.
$ShareName = "1cshare"
#OU Active Directory, 1c
$OU = âOU=1C,OU=Resources,DC=domain,DC=ruâ
# DFS , 1
#, , , .
$1CConfigFolder = "\\domain.ru\DfsShare\1cconfig\"
#
#
$strSheetName = 'Sheet1$' # 1$
#----------------------------------------------------------
#
#----------------------------------------------------------
$dataFilePath = $localPath + "\$dataFile"
$localPath = $PSScriptRoot
# 1
$1CBasesCFG = $1CConfigFolder + â1CEStart.cfgâ
#
# ACL .
$GRRS_1C_ConfigBasesRO = "GRRS_1C_ConfigBasesRO"
#
# ACL .
$GRRS_1CBases = "GRRS_1CBases"
# 1
$GR_1CAdmins = "GRUS_1Cadmins"
#
If (!(Test-Path -Path $dataFilePath -PathType Any))
{
Write-Host "[ERROR]`t $dataFile ! , $dataFile !" -ForegroundColor Red
Exit 1
}
# Excel- , SQLDB
# Microsoft Access Database Engine 2010 Redistributable
# www.microsoft.com/en-us/download/details.aspx?id=13255
# , . Office
# . , .
$strProvider = "Provider=microsoft.ace.oledb.12.0"
$strDataSource = "Data Source = $dataFilePath"
$strExtend = "Extended Properties=Excel 8.0"
$strQuery = "Select * from [$strSheetName]"
$objConn = New-Object System.Data.OleDb.OleDbConnection("$strProvider;$strDataSource;$strExtend")
$sqlCommand = New-Object System.Data.OleDb.OleDbCommand($strQuery)
$sqlCommand.Connection = $objConn
$objConn.open()
$DataReader = $sqlCommand.ExecuteReader()
#
$AccessArr = New-Object System.Collections.ArrayList
#
While($DataReader.Read())
{
# (.replace(' ','')), - .
$BaseName = $DataReader[2].Tostring().replace(' ','')
$FolderName = $DataReader[3].Tostring().replace(' ','')
$GroupName = $DataReader[4].Tostring().replace(' ','')
# $AccessArr
[void] $AccessArr.Add($DataReader[5].Tostring().replace(' ',''))
[void] $AccessArr.Add($DataReader[6].Tostring().replace(' ',''))
[void] $AccessArr.Add($DataReader[7].Tostring().replace(' ',''))
[void] $AccessArr.Add($DataReader[8].Tostring().replace(' ',''))
[void] $AccessArr.Add($DataReader[8].Tostring().replace(' ',''))
[void] $AccessArr.Add($DataReader[10].Tostring().replace(' ',''))
[void] $AccessArr.Add($DataReader[11].Tostring().replace(' ',''))
# . , .
# . .
$FullPathBase = "\" + "\" + $1Cserver + "\" + $Sharename + "\" + $FolderName
# AD
$CommentBase = ââ + â â + $BaseName + â â
$CommentPath = $FullPathBase
$Comment = $CommentBase + $CommentPath
# ,
$ConfigBaseFile = $1cConfigFolder + $FolderName + â.v8iâ
# v8i
# 1, Connect=File
$ConfigBaseFileContent ="[$BaseName]
Connect=File=$FullPathBase
ClientConnectionSpeed=Normal
App=Auto
WA=1
Version=8.3
"
# v8i- 1CEStart.cfg
# v8i-
$ConfigBaseFileContent | Set-Content $ConfigBaseFile -Encoding UTF8
# v8i- 1CEStart.cfg
$1CBasesCFGContent = "CommonInfoBases=$ConfigBaseFile"
# v8i- 1CEStart.cfg
$1CBasesCFGContent | Add-Content $1CBasesCFG -Encoding UTF8
# , .
New-ADGroup -GroupScope DomainLocal -GroupCategory Security `
-name $GroupName -Path $OU -Description $CommentPath -OtherAttributes @{info="$Comment"}
#
Add-ADGroupMember -Identity $GRRS_1C_ConfigBasesRO $GroupName
#
Add-ADGroupMember -Identity $GRRS_1CBases $GroupName
# .
foreach ($i in $AccessArr)
{
if ($i)
{
Add-ADGroupMember -Identity $GroupName $i
}
}
#
New-item -Path $FullPathBase -ItemType directory
#
$acl = Get-Acl $FullPathBase
$GroupOwner = New-Object System.Security.Principal.NTAccount("Builtin", "Administrators")
$acl.SetOwner($GroupOwner)
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule(âAdministratorsâ,âModify,FullControl, Synchronizeâ, âContainerInherit, ObjectInheritâ, âNoneâ, âAllowâ)
$acl.AddAccessRule($rule)
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule(âDomain adminsâ,âModify,FullControl, Synchronizeâ, âContainerInherit, ObjectInheritâ, âNoneâ, âAllowâ)
$acl.AddAccessRule($rule)
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule(â$GroupNameâ,âModify, Synchronizeâ, âContainerInherit, ObjectInheritâ, âNoneâ, âAllowâ)
$acl.AddAccessRule($rule)
$rule = New-Object System.Security.AccessControl.FileSystemAccessRule(â$GR_1CAdminsâ,âModify, Synchronizeâ, âContainerInherit, ObjectInheritâ, âNoneâ, âAllowâ)
$acl.AddAccessRule($rule)
$acl.SetAccessRuleProtection($True, $False)
Set-Acl $FullPathBase $acl
# v8i-
$aclfl = Get-Acl $ConfigBaseFile
$GroupOwner = New-Object System.Security.Principal.NTAccount("Builtin", "Administrators")
$aclfl.SetOwner($GroupOwner)
$rulefl = New-Object System.Security.AccessControl.FileSystemAccessRule(âAdministratorsâ,âModify,FullControl, Synchronizeâ, âAllowâ)
$aclfl.AddAccessRule($rulefl)
$rulefl = New-Object System.Security.AccessControl.FileSystemAccessRule(âDomain adminsâ,âModify,FullControl, Synchronizeâ, âAllowâ)
$aclfl.AddAccessRule($rulefl)
$rulefl = New-Object System.Security.AccessControl.FileSystemAccessRule(â$GroupNameâ,âReadAndExecute, Synchronizeâ, âAllowâ)
$aclfl.AddAccessRule($rulefl)
$rulefl = New-Object System.Security.AccessControl.FileSystemAccessRule(â$GR_1CAdminsâ,âReadAndExecute, Synchronizeâ, âAllowâ)
$aclfl.AddAccessRule($rulefl)
Set-Acl $ConfigBaseFile $aclfl
# 1CEStart.cfg
$aclcf = Get-Acl $1CBasesCFG
$GroupOwner = New-Object System.Security.Principal.NTAccount("Builtin", "Administrators")
$aclcf.SetOwner($GroupOwner)
$rulecf = New-Object System.Security.AccessControl.FileSystemAccessRule(âAdministratorsâ,âModify,FullControl, Synchronizeâ, âAllowâ)
$aclcf.AddAccessRule($rulecf)
$rulecf = New-Object System.Security.AccessControl.FileSystemAccessRule(âDomain adminsâ,âModify,FullControl, Synchronizeâ, âAllowâ)
$aclcf.AddAccessRule($rulecf)
$rulecf = New-Object System.Security.AccessControl.FileSystemAccessRule(â$GRRS_1C_ConfigBasesROâ,âReadAndExecute, Synchronizeâ, âAllowâ)
$aclcf.AddAccessRule($rulecf)
$rulecf = New-Object System.Security.AccessControl.FileSystemAccessRule(â$GR_1CAdminsâ,âReadAndExecute, Synchronizeâ, âAllowâ)
$aclcf.AddAccessRule($rulecf)
Set-Acl $1CBasesCFG $aclcf
}
#
$dataReader.close()
$objConn.close()
èµ·ããããå°é£
ã©ã®ãããªçç±ã§çè§£ã§ããŸããã§ããããäœããã®çç±ã§ããã¹ãŠã®ã¹ã¯ãªãããèšè¿°ãããŠãããã®ã®ãããŒã¿ããŒã¹ã®ãããã©ã«ããŒã§
ããã¹ãŠã®åãªããžã§ã¯ãã®ã¢ã¯ã»ã¹èš±å¯ããã®ãªããžã§ã¯ãã®ç¶æ¿å¯èœãªã¢ã¯ã»ã¹èš±å¯ã§çœ®ãæããããªãã·ã§ã³ã
ãªã³ã«ãªããŸããã§ãã ãããã£ãŠãããŒã¿ããŒã¹ãæ°ããå Žæã«ã³ããŒããåŸãã³ããŒããããã¡ã€ã«ã«å¯Ÿããæš©éã芪ãã©ã«ããŒããç¶æ¿ãããŠãããã©ããã確èªããŠãã ããã
ãããã«
ååãã¹ã¯ãªããã¯ããªãããææžåãããŠããŸãããçŽ1æéã§ã²ãã®äžã«æžãããŠããŸãã ãã®äœ¿çšã«é¢ãããã¹ãŠã®è²¬ä»»ã¯ãUFOã®ã¿ã«ãããŸãã
ç§ïŒãšæãïŒã¯ãPowerShellã§é¢æ°ãæ£ããäœæããæ¹æ³ããªã¯ãšã¹ããäœæãããã©ã¡ãŒã¿ãŒã確èªããæ¹æ³ããã®ã³ã°ãå®è£
ããæ¹æ³ãã¹ã¯ãªããã®ãã«ããäœæããæ¹æ³ãªã©ãç¥ã£ãŠããŸãããããã¯ãã¹ãŠäžå¿
èŠã ãšæããŸãã ãã ããããã€ãã®ãã§ãã¯ãããšãã°ãæ§æãŸãã¯ãããªãã¯ãã©ã«ããŒã®ãããã£ã¬ã¯ããªãå®è¡ã§ããŸãã ããããç§ã¯ãä»åã§ã¯ãªãããã®ãããªä»äºã§ã¯ãªããšæããŸãã
#ChangeLog- Sergey-S-Kovalevãææããäžæ£ç¢ºããä¿®æ£ã
- ãŠãŒã¶ãŒãé
ån1nj4p0w3rã«è¿œå ãããæ¹æ³ã倿ŽããŸããã
- Active Directoryã¢ãžã¥ãŒã«ã®æ€èšŒã远å ã
- ãã£ã¬ã¯ããªå
ã®ããŒã¿ãæã€ãã¡ã€ã«ã®ååšã®ãã§ãã¯ã远å ããŸããã
ãããããé¡ãããŸãïŒ
ãã¹ãŠã®äººã«è¯ãïŒ