1
0
mirror of https://github.com/samba-team/samba.git synced 2025-01-03 01:18:10 +03:00
samba-mirror/source4
Björn Baumbach 22af043d2f CVE-2013-4476: s4:libtls: check for safe permissions of tls private key file (key.pem)
If the tls key is not owned by root or has not mode 0600 samba will not
start up.

Bug: https://bugzilla.samba.org/show_bug.cgi?id=10234

Pair-Programmed-With: Stefan Metzmacher <metze@samba.org>

Signed-off-by: Björn Baumbach <bb@sernet.de>
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Stefan Metzmacher <metze@samba.org>

Autobuild-User(master): Karolin Seeger <kseeger@samba.org>
Autobuild-Date(master): Mon Nov 11 13:07:16 CET 2013 on sn-devel-104
2013-11-11 13:07:16 +01:00
..
auth auth-kerberos: add the credentials.h so that enum credentials_obtained is defined 2013-10-27 02:25:46 +01:00
build/pasn1
cldap_server s4: Fix a -Wunused-value warning 2012-09-26 21:52:00 +02:00
client Make sure to set umask() before calling mkstemp(). 2013-03-06 01:16:34 +01:00
cluster source4/cluster and source4/ntvfs: convert to dbwrap, add ntdb option. 2013-04-12 14:59:42 -07:00
dns_server dns: Update TODO list 2013-07-29 09:12:17 +02:00
dsdb s4-dsdb: instanceType NC_HEAD is only allowed combined with WRITE for an originating add operation 2013-11-03 16:17:30 +01:00
echo_server lib/param: Create a seperate server role for "active directory domain controller" 2012-06-15 09:18:33 +02:00
heimdal heimdal: fixed -Werror=format error in com_err 2012-08-02 08:59:24 +02:00
heimdal_build waf: replace dependency to libintl with samba_intl 2013-08-12 00:46:34 +02:00
include Replace all uses of setXX[ug]id() and setgroups with samba_setXX[ug]id() calls. 2012-06-28 17:15:16 -07:00
kdc s4-kdc: Improve grammer and clarity of password change failure messages. 2012-09-01 03:33:21 +02:00
ldap_server auth/gensec: treat struct gensec_security_ops as const if possible. 2013-08-10 09:19:04 +02:00
lib CVE-2013-4476: s4:libtls: check for safe permissions of tls private key file (key.pem) 2013-11-11 13:07:16 +01:00
libcli libcli/smb: move Filesystem Attributes defines to smb_constants.h 2013-10-17 16:08:29 +02:00
libnet python/drs: Ensure to pass in the local invocationID during the domain join 2013-09-19 12:25:41 -07:00
librpc s4:librpc: let dcerpc_schannel_key_recv() return netlogon_creds_CredentialState 2013-10-17 08:49:00 +13:00
nbt_server s4:nbt_server: avoid talloc_reference() 2013-08-12 16:48:51 +12:00
ntp_signd build: Build with system md5.h on OpenIndiana 2013-06-19 21:32:36 +02:00
ntptr spoolss: make spoolss deal with ndr64 SetForm by using proper container object. 2013-01-17 17:11:37 +01:00
ntvfs ntvfs: Fix CID 1107225 Resource leak 2013-10-21 16:34:35 -07:00
param s4:libcli:smb2: add the smb2_capabilities to the smbcli_options 2013-10-05 14:04:07 +02:00
rpc_server s4-lsa: Make sure we also duplicate the domain_name. 2013-11-07 18:58:44 +01:00
script lib/param move source4 param code to the top level 2011-10-11 13:41:34 +11:00
scripting samba-tool domain join subdomain: Rework sambadns.py to allow setup of DomainDNSZone only 2013-10-11 10:27:49 +02:00
selftest selftest: Add release-4-1-0rc3 saved provision 2013-09-22 14:39:51 -07:00
setup samba-tool domain join subdomain: Rework sambadns.py to allow setup of DomainDNSZone only 2013-10-11 10:27:49 +02:00
smb_server s4-smb_server: Fix a use after free. 2013-11-08 09:45:10 -08:00
smbd s4:server: avoid calling into nss_winbind from within 'samba' 2013-07-10 23:18:06 +02:00
torture Add regression test for bug #10229 - No access check verification on stream files. 2013-11-04 23:10:10 +01:00
utils ldb: Do not build libldb-cmdline when using system ldb. 2013-09-10 12:52:26 +02:00
web_server Move python modules from source4/scripting/python/ to python/. 2013-03-02 03:57:34 +01:00
winbind s4-winbindd: Do not terminate a connection that is still pending (bug #9820) 2013-07-10 06:57:06 +02:00
wrepl_server s4:wrepl_out_helpers.c: avoid talloc_reference() in most cases 2013-08-12 16:48:54 +12:00
.clang_complete s3-build: Add .clang_complete. 2011-10-27 17:09:50 +02:00
.valgrind_suppressions
wscript_build build: Add missing deps and make MESSAGING a private library 2012-06-07 06:45:06 +02:00