Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
preventing false positive by checking ADS_RIGHT_DS_CONTROL_ACCESS bit flag,
before this commit, there might false positve, when an ace has Enroll uuid without ADS_RIGHT_DS_CONTROL_ACCESS being set in Mask field, this happens when we unselect the checkbox which indicate the permission is allow or denied
before we uncheck the checkbox, we have CR(which means control access righ ) set on mask field, and the Enroll is also showed in the ace
if we uncheck the checkbox
we can find the CR flag is not set while the Enroll permission uuid still showed in the ace
when this happens, certipy still mark this cert template as "user can enroll", but actually it will be denied.