<div class="content" name="BaseRegGetKeySecurity" uuid="b0e1868c-f4fd-4b43-959f-c0f0cac3ee26"><p>The BaseRegGetKeySecurity method is called by the client. In
response, the server returns a copy of the security descriptor that protects
the specified open registry key.</p><dl>
<dd>
<div><pre> error_status_t BaseRegGetKeySecurity(
   [in] RPC_HKEY hKey,
   [in] SECURITY_INFORMATION SecurityInformation,
   [in] PRPC_SECURITY_DESCRIPTOR pRpcSecurityDescriptorIn,
   [out] PRPC_SECURITY_DESCRIPTOR pRpcSecurityDescriptorOut
 );
</pre></div>
</dd></dl><p><b>hKey: </b>A handle to a key that MUST have been
opened previously by using one of the open methods that are specified in section
<a href="053e8515-dbae-47ea-a7c6-6dc054e3a48f" data-linktype="relative-path">3.1.5</a>: <a href="956a3052-6580-43ee-91aa-aaf61726149b" data-linktype="relative-path">OpenClassesRoot</a>, <a href="ec140ed9-4d00-4c03-a15c-c7245a497ed5" data-linktype="relative-path">OpenCurrentUser</a>, <a href="6cef29ae-21ba-423f-9158-05145ac80a5b" data-linktype="relative-path">OpenLocalMachine</a>, <a href="7b514c63-6cad-4fe1-9780-743959e377e6" data-linktype="relative-path">OpenPerformanceData</a>, <a href="694e57f4-da3e-4285-8b71-3181d71d6cd1" data-linktype="relative-path">OpenUsers</a>, <a href="c7186ae2-1c82-45e9-933b-97d9873657e8" data-linktype="relative-path">BaseRegCreateKey</a>, <a href="8cb48f55-19e1-4ea2-8d76-dd0f6934f0d9" data-linktype="relative-path">BaseRegOpenKey</a>, <a href="160767d7-83cf-4718-a4f3-d864faee3bb1" data-linktype="relative-path">OpenCurrentConfig</a>, <a href="44954f6d-ef2c-4ec1-a27d-32b9b87e3c8a" data-linktype="relative-path">OpenPerformanceText</a>, <a href="3626fa8a-b20f-4243-bf85-cdb615ed2ca0" data-linktype="relative-path">OpenPerformanceNlsText</a>.</p><p><b>SecurityInformation:</b> The information that is
needed to determine the type of security that is returned in <i>pRpcSecurityDescriptorOut</i>.
See <a href="aa272b32-d7b9-4080-8195-f1bd6c33c6d7" data-linktype="relative-path">SECURITY_INFORMATION</a>
(includes a list of possible <a href="261b039d-95d9-4749-9680-db1851d03945#gt_7bc13a0c-ca1a-4c78-b1bf-67e243f778bb" data-linktype="relative-path">values</a>).</p><p><b>pRpcSecurityDescriptorIn: </b>A pointer to a
buffer containing a security descriptor. The client MUST provide a pointer to
an <a href="9729e781-8eb9-441b-82ca-e898f98d29c2" data-linktype="relative-path">RPC_SECURITY_DESCRIPTOR</a>
with arbitrary contents. The server uses the size of this security descriptor
to validate the client has the correct amount of memory allocated for the
RPC_SECURITY_DESCRIPTOR pointed to by the <i>pRpcSecurityDescriptorOut</i>
parameter</p><p><b>pRpcSecurityDescriptorOut:</b> A pointer to a
buffer to which the requested security descriptor MUST be written.</p><p><b>Return Values: </b>The method returns 0
(ERROR_SUCCESS) to indicate success; otherwise, it returns a nonzero error
code, as specified in <a href="../ms-erref/1bc92ddf-b79e-413c-bbaa-99a5281a6c90" data-linktype="relative-path">[MS-ERREF]</a>
section <a href="../ms-erref/18d8fbe8-a967-4f1c-ae50-99ca8e491d2d" data-linktype="relative-path">2.2</a>.
The most common error codes are listed in the following table.</p><dl>
<dd>
<table><thead>
  <tr>
   <th>
   <p>Return value/code</p>
   </th>
   <th>
   <p>Description</p>
   </th>
  </tr>
 </thead><tbody><tr>
  <td>0x0000000E ERROR_OUTOFMEMORY</td>
  <td>Not enough storage is available to complete this operation.</td>
 </tr><tr>
  <td>0x00000057 ERROR_INVALID_PARAMETER</td>
  <td>A parameter is incorrect.</td>
 </tr><tr>
  <td>0x00000013 ERROR_WRITE_PROTECT</td>
  <td>A read or write operation was attempted to a volume after it was dismounted. The server can no longer service registry requests because server shutdown has been initiated.</td>
 </tr></tbody></table>
</dd></dl><p>Server Operations</p><p>If the registry server can no longer service registry
requests because server shutdown has been initiated (<b>SHUTDOWNINPROGRESS</b>
is set to TRUE), the server MUST return ERROR_WRITE_PROTECT.</p><p>If <i>hKey</i> refers to a key that is one of the predefined
performance handles (HKEY_PERFORMANCE_DATA, HKEY_PERFORMANCE_TEXT or
HKEY_PERFORMANCE_NLSTEXT) and the client has set bit 0x8
(SACL_SECURITY_INFORMATION) in the <i>SecurityInformation</i> parameter, the
server MUST fail the method and return ERROR_PRIVILEGE_NOT_HELD.</p><p>The server MUST first validate that the <i>hKey</i>
parameter is currently an open handle which MUST have been opened previously
using one of the methods specified in section 3.1.5. If the <i>hKey</i>
parameter is not an already opened handle, the server MUST return
ERROR_INVALID_PARAMETER.</p><p>In response to this request from the client, for a
successful operation, the server MUST return a copy of the <a href="../ms-dtyp/7d4dac05-9cef-4563-a058-f108abecce1d" data-linktype="relative-path">SECURITY_DESCRIPTOR</a>
that is associated with the registry key that is specified by the <i>hKey</i>
parameter. </p><p>The server MUST return the security descriptor in the buffer
that is pointed to by the <i>pRpcSecurityDescriptorOut</i> parameter. The
returned values in the <i>pRpcSecurityDescriptorOut</i> parameter depend on the
values that are requested by the client in the <i>SecurityInformation</i>
parameter. See SECURITY_INFORMATION.</p><p>The server MUST return 0 to indicate success or an
appropriate error code (as specified in [MS-ERREF]) to indicate an error.</p><p>If the server returns 122 (ERROR_INSUFFICIENT_BUFFER), the
size of the output buffer pointed to by the <i>pRpcSecurityDescriptorOut</i>
parameter is not large enough. The required output buffer size is indicated by
the <b>cbInSecurityDescriptor</b> field of the RPC_SECURITY_DESCRIPTOR
structure pointed to by the <i>pRpcSecurityDescriptorOut</i> parameter. The
remaining fields of the RPC_SECURITY_DESCRIPTOR structure MUST be NULL.</p></div>