1
0
mirror of https://github.com/samba-team/samba.git synced 2025-01-08 21:18:16 +03:00
samba-mirror/libcli/auth
Stefan Metzmacher 08e2a93393 CVE-2022-38023 docs-xml/smbdotconf: change 'reject md5 servers' default to yes
AES is supported by Windows >= 2008R2 and Samba >= 4.0 so there's no
reason to allow md5 servers by default.

Note the change in netlogon_creds_cli_context_global() is only cosmetic,
but avoids confusion while reading the code. Check with:

 git show -U35 libcli/auth/netlogon_creds_cli.c

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15240

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Ralph Boehme <slow@samba.org>
(cherry picked from commit 1c6c112990)
2022-12-14 10:28:16 +00:00
..
tests smbdes: remove old unused DES builtin-crypto 2019-12-10 00:30:31 +00:00
credentials.c CVE-2020-1472(ZeroLogon): libcli/auth: reject weak client challenges in netlogon_creds_server_init() 2020-09-18 12:48:38 +00:00
credentials.h
libcli_auth.h
msrpc_parse.c
msrpc_parse.h
netlogon_creds_cli.c CVE-2022-38023 docs-xml/smbdotconf: change 'reject md5 servers' default to yes 2022-12-14 10:28:16 +00:00
netlogon_creds_cli.h CVE-2022-38023 libcli/auth: add/use netlogon_creds_cli_warn_options() 2022-12-14 10:28:16 +00:00
ntlm_check.c auth: Avoid casts in ntlm_check.c 2020-01-06 03:12:19 +00:00
ntlm_check.h
pam_errors.c
pam_errors.h
proto.h CVE-2020-1472(ZeroLogon): libcli/auth: add netlogon_creds_is_random_challenge() to avoid weak values 2020-09-18 12:48:38 +00:00
schannel_proto.h
schannel_state_tdb.c lib: Fix an error path memleak in schannel_get_creds_state() 2019-11-14 22:26:30 +00:00
schannel_state.h
schannel.h
session.c sess_crypt_blob can only crypt blobs whose size divides by 8 2019-12-10 00:30:31 +00:00
smbdes.c smbdes: remove old unused DES builtin-crypto 2019-12-10 00:30:31 +00:00
smbencrypt.c libcli:auth: Keep passwords from convert_string_talloc() secret 2022-09-18 16:46:09 +00:00
spnego_parse.c CVE-2020-10704: lib util asn1: Add ASN.1 max tree depth 2020-05-04 02:59:31 +00:00
spnego_proto.h
spnego.h
wscript_build librpc: Remove the gensec dependency from library dcerpc-binding 2021-04-06 23:33:14 +00:00