部分Windows客户端上的Named Pipe安全问题排查求助
解决Named Pipe添加访问规则时的身份引用翻译错误问题
问题原因
报错“Some or all identity references could not be translated.”的核心原因是:你代码里直接使用的"Users"是英文系统下的用户组名称,但Windows的内置用户组名称会随系统语言本地化(比如中文系统是“用户”,日文系统有对应翻译)。在非英文系统上,系统无法将"Users"映射到本地实际存在的用户组,因此抛出身份引用无法翻译的错误。
解决方案
方案1:使用固定SID(推荐)
Windows内置用户组的安全标识符(SID)是固定的,不受系统语言影响。Users组对应的WellKnownSidType是BuiltinUsersSid,直接用它创建SecurityIdentifier对象来添加访问规则,适配所有语言版本的Windows:
PipeSecurity pipeSecurity = new PipeSecurity(); SecurityIdentifier usersSid = new SecurityIdentifier(WellKnownSidType.BuiltinUsersSid, null); pipeSecurity.AddAccessRule(new PipeAccessRule(usersSid, PipeAccessRights.ReadWrite | PipeAccessRights.CreateNewInstance, AccessControlType.Allow));
方案2:动态获取本地化组名
如果需要使用组名而非SID,可以先通过SID获取当前系统的本地化Users组名称,再添加规则:
PipeSecurity pipeSecurity = new PipeSecurity(); // 通过SID转换获取本地Users组的名称 string localUsersGroupName = new SecurityIdentifier(WellKnownSidType.BuiltinUsersSid, null) .Translate(typeof(NTAccount)) .Value; pipeSecurity.AddAccessRule(new PipeAccessRule(localUsersGroupName, PipeAccessRights.ReadWrite | PipeAccessRights.CreateNewInstance, AccessControlType.Allow));
补充说明
之前的代码在部分电脑正常运行,是因为这些电脑使用的是英文Windows系统,"Users"正好匹配系统内置的用户组名称;而报错的电脑是其他语言版本的Windows,组名已被本地化,导致匹配失败。
内容的提问来源于stack exchange,提问作者Michael
相关产品推荐
相关产品推荐

