1
0
mirror of https://github.com/samba-team/samba.git synced 2025-01-06 13:18:07 +03:00
samba-mirror/docs-xml/smbdotconf/security
Alexander Bokovoy 0ed55bfe08 sync machine password to keytab: handle FreeIPA use case
FreeIPA uses own procedure to retrieve keytabs and during the setup of
Samba on FreeIPA client the keytab is already present, only machine
account needs to be set in the secrets database.

'sync machine password to keytab' option handling broke this use case by
always attempting to contact a domain controller and failing to do so
(Fedora bug https://bugzilla.redhat.com/show_bug.cgi?id=2309199).

The original synchronizing machine account password to keytab feature
did not have a mechanism to disable its logic at all.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15715

Signed-off-by: Alexander Bokovoy <ab@samba.org>
Reviewed-by: Pavel Filipenský <pfilipensky@samba.org>

Autobuild-User(master): Alexander Bokovoy <ab@samba.org>
Autobuild-Date(master): Fri Sep 13 13:16:09 UTC 2024 on atb-devel-224

(cherry picked from commit 4f577c7b68)

Autobuild-User(v4-21-test): Jule Anger <janger@samba.org>
Autobuild-Date(v4-21-test): Fri Sep 20 15:40:36 UTC 2024 on atb-devel-224
2024-09-20 15:40:36 +00:00
..
accessbasedshareenum.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
aclclaimsevaluation.xml docs-xml: Add new parameter "acl claims evaluation" 2023-09-26 23:45:35 +00:00
aclflaginheritedcanonicalization.xml docs-xml: Fix documentation 2023-10-25 22:23:37 +00:00
aclgroupcontrol.xml manpage: corrected small typo error 2015-11-02 14:43:15 +01:00
adminusers.xml docs:smbdotconf: change type to cmdlist where needed. 2015-07-31 01:55:32 +02:00
algorithmicridbase.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
allowdcerpcauthlevelconnect.xml CVE-2022-38023 docs-xml: improve wording for several options: "yields precedence" -> "is over-riden" 2022-12-13 13:07:29 +00:00
allowtrusteddomains.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
binddnsdir.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
checkpasswordscript.xml smbdotconf: mark "check password script" with substitution="1" 2019-11-27 10:25:34 +00:00
clientipcsigning.xml docs-xml: Use 'desired' and 'required' for option 'client ipc signing' 2021-04-28 03:43:34 +00:00
clientlanmanauth.xml docs: deprecate "client lanman auth" 2020-08-18 00:10:40 +00:00
clientntlmv2auth.xml docs: deprecate "client NTLMv2 auth" 2020-08-18 00:10:40 +00:00
clientplaintextauth.xml docs: deprecate "client plaintext auth" 2020-08-18 00:10:40 +00:00
clientprotection.xml lib:param: Add 'client protection' config option 2021-04-28 03:43:34 +00:00
clientschannel.xml CVE-2022-38023 docs-xml: improve wording for several options: "yields precedence" -> "is over-riden" 2022-12-13 13:07:29 +00:00
clientsigning.xml docs-xml: Use 'desired' and 'required' for option 'client signing' 2021-04-28 03:43:34 +00:00
clientsmbencrypt.xml docs-xml: Add 'client smb encrypt' 2020-08-19 16:22:40 +00:00
clientsmbencryptionalgos.xml docs-xml: use upper case for "{client,server} smb3 {signing,encryption} algorithms" values 2021-09-08 16:37:07 +00:00
clientsmbsigningalgos.xml docs-xml: use upper case for "{client,server} smb3 {signing,encryption} algorithms" values 2021-09-08 16:37:07 +00:00
clientusekerberos.xml docs-xml: Fix spelling 2023-09-11 02:42:41 +00:00
createmask.xml docs:smbdotconf: change type to octal where needed 2015-07-31 01:55:32 +02:00
debugencryption.xml docs-xml: add "debug encryption" global parm 2019-02-09 18:30:14 +01:00
dedicatedkeytabfile.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
directorymask.xml docs:smbdotconf: change type to octal where needed 2015-07-31 01:55:32 +02:00
directorysecuritymask.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
encryptpasswords.xml docs: Deprecate "encrypt passwords = no" 2019-09-05 02:45:28 +00:00
forcecreatemode.xml docs:smbdotconf: change type to octal where needed 2015-07-31 01:55:32 +02:00
forcedirectorymode.xml docs:smbdotconf: change type to octal where needed 2015-07-31 01:55:32 +02:00
forcedirectorysecuritymode.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
forcegroup.xml smbdotconf: mark "force group" with substitution="1" 2019-11-27 10:25:33 +00:00
forcesecuritymode.xml
forceunknownacluser.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
forceuser.xml smbdotconf: mark "force user" with substitution="1" 2019-11-27 10:25:33 +00:00
guestaccount.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
guestok.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
guestonly.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
hostsallow.xml Revert "docs-xml: Update documentation for removal of NIS support" 2022-06-09 21:45:28 +00:00
hostsdeny.xml docs:smbdotconf: change type to cmdlist where needed. 2015-07-31 01:55:32 +02:00
inheritacls.xml docs-xml: some fixes and updates for ea and acl docs in smb.conf 2022-09-12 02:30:36 +00:00
inheritowner.xml docs: Fix double-word in "inherit owner" manpage 2022-10-21 03:57:33 +00:00
inheritpermissions.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
invalidusers.xml Revert "docs-xml: Update documentation for removal of NIS support" 2022-06-09 21:45:28 +00:00
kdcdefaultdomainsupportedenctypes.xml CVE-2022-37966 param: let "kdc default domain supportedenctypes = 0" mean the default 2022-12-13 13:07:30 +00:00
kdcenablefast.xml docs-xml: add 'kdc enable fast' option 2022-03-11 17:10:29 +00:00
kdcforceenablerc4weaksessionkeys.xml CVE-2022-37966 param: Add support for new option "kdc force enable rc4 weak session keys" 2022-12-13 13:07:29 +00:00
kdcsupportedenctypes.xml CVE-2022-37966 param: Add support for new option "kdc supported enctypes" 2022-12-13 13:07:30 +00:00
kerberosencryptiontypes.xml CVE-2022-37966 docs-xml/smbdotconf: "kerberos encryption types = legacy" should not be used 2022-12-13 13:07:29 +00:00
kerberosmethod.xml docs:smbdotconf: Update 'kerberos method' with 'sync machine password to keytab' 2024-08-13 15:37:12 +00:00
kpasswdport.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
krb5port.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
lanmanauth.xml s4-auth: Remove last traces of LanMan authentiation support in the AD DC. 2022-03-29 03:32:57 +00:00
lognttokencommand.xml smbdotconf: mark "log nt token command" with substitution="1" 2019-11-27 10:25:35 +00:00
maptoguest.xml docs:smbdotconf: add enumlist property to parameters where missing 2015-07-31 01:55:29 +02:00
mindomainuid.xml CVE-2020-25717: loadparm: Add new parameter "min domain uid" 2021-11-09 19:45:32 +00:00
mitkdccommand.xml docs-xml: remove SWAT specific flags 2019-11-27 10:25:37 +00:00
nt_hash_store.xml dsdb: Allow password history and password changes without an NT hash 2022-06-26 22:10:29 +00:00
ntlmauth.xml docs-xml: Fix code spelling 2023-08-14 04:57:34 +00:00
ntpsigndsocketdirectory.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
nullpasswords.xml docs:smbdotconf: add deprecated flags where missing. 2015-07-31 01:55:31 +02:00
obeypamrestrictions.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
oldpasswordallowedperiod.xml docs:smbdotconf: fix a typo in oldpasswordallowedperiod.xml 2020-12-17 13:59:37 +00:00
pampasswordchange.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
passdbbackend.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
passdbexpandexplicit.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
passwdchat.xml docs-xml: Update documentation for removal of NIS support 2021-04-22 17:57:30 +00:00
passwdchatdebug.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
passwdchattimeout.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
passwdprogram.xml smbdotconf: mark "passwd program" with substitution="1" 2019-11-27 10:25:35 +00:00
passwordhashgpgkeyids.xml docs-xml/smbdotconf: add "password hash gpg key ids" option 2016-07-22 16:03:27 +02:00
passwordhashuserpasswordschemes.xml docs: configuration options for extra password hashes 2017-05-25 02:25:12 +02:00
passwordserver.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
preloadmodules.xml docs:smbdotconf: change type to cmdlist where needed. 2015-07-31 01:55:32 +02:00
privatedir.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
rawntlmv2auth.xml docs: deprecate "raw NTLMv2 auth" 2020-08-18 00:10:40 +00:00
readlist.xml docs:smbdotconf: change type to cmdlist where needed. 2015-07-31 01:55:32 +02:00
readonly.xml docs:smbdotconf: 'write ok' is a synonym of 'writeable' not of 'read only' 2015-07-31 01:55:31 +02:00
renameuserscript.xml smbdotconf: mark "rename user script" with substitution="1" 2019-11-27 10:25:36 +00:00
restrictanonymous.xml docs-xml: Update documentation for 'restrict anonymous' option 2019-02-07 17:23:18 +01:00
rootdirectory.xml docs-xml: Fix reference to 'wide links' parameter 2022-10-05 04:23:32 +00:00
sambakcccommand.xml docs:smbdotconf: change type to cmdlist where needed. 2015-07-31 01:55:32 +02:00
security.xml docs-xml: Remove reference to invalid 'user' parameter 2022-10-05 04:23:32 +00:00
securitymask.xml
serverrole.xml docs-xml: Fix spelling in smb.conf manpage 2023-04-04 07:31:36 +00:00
serverschannel.xml CVE-2022-38023 docs-xml/smbdotconf: add "server schannel require seal[:COMPUTERACCOUNT]" options 2022-12-13 13:07:29 +00:00
serverschannelrequireseal.xml CVE-2022-38023 docs-xml/smbdotconf: The "server schannel require seal[:COMPUTERACCOUNT]" options are also honoured by s3 netlogon server. 2023-01-09 14:23:36 +00:00
serversigning.xml CVE-2016-2114: docs-xml: let the "smb signing" documentation reflect the reality 2016-04-12 19:25:26 +02:00
serversmbencrypt.xml param: Create and use enum_smb_encryption_vals 2020-08-19 16:22:40 +00:00
serversmbencryptionalgos.xml docs-xml: use upper case for "{client,server} smb3 {signing,encryption} algorithms" values 2021-09-08 16:37:07 +00:00
serversmbsigningalgos.xml docs-xml: use upper case for "{client,server} smb3 {signing,encryption} algorithms" values 2021-09-08 16:37:07 +00:00
smbencrypt.xml param: Create and use enum_smb_encryption_vals 2020-08-19 16:22:40 +00:00
smbpasswdfile.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
syncmachinepasswordscript.xml docs-xml: Fix script location in syncmachinepasswordscript.xml 2024-08-20 07:39:20 +00:00
syncmachinepasswordtokeytab.xml sync machine password to keytab: handle FreeIPA use case 2024-09-20 15:40:36 +00:00
tlscadirs.xml docs-xml: add 'tls trust system cas' and 'tls ca directories' options 2024-04-23 23:50:34 +00:00
tlscafile.xml docs-xml: add 'tls trust system cas' and 'tls ca directories' options 2024-04-23 23:50:34 +00:00
tlscertfile.xml Extended the documentation for the "tls certfile" parameter in the smb.conf. 2024-06-27 05:33:17 +00:00
tlscrlfile.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
tlsdhparamsfile.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
tlsenabled.xml docs:smbdotconf: remove swat-specific flags. 2015-05-02 00:56:31 +02:00
tlskeyfile.xml docs-xml: remove explicit "constant" 2019-11-27 10:25:37 +00:00
tlspriority.xml tls: Use NORMAL:-VERS-SSL3.0 as the default configuration 2020-07-01 14:56:33 +00:00
tlstrustsystemcas.xml docs-xml: add 'tls trust system cas' and 'tls ca directories' options 2024-04-23 23:50:34 +00:00
tlsverifypeer.xml docs-xml: add 'tls trust system cas' and 'tls ca directories' options 2024-04-23 23:50:34 +00:00
unixpasswordsync.xml docs-xml/smbdotconf: reference "unix password sync" with "password hash gpg key ids" 2016-07-22 16:03:27 +02:00
usernamelevel.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
usernamemap.xml Revert "docs-xml: Update documentation for removal of NIS support" 2022-06-09 21:45:28 +00:00
usernamemapcachetime.xml docs:smbdotconf: make formatting of headers uniform. 2015-07-31 01:55:29 +02:00
usernamemapscript.xml smb.conf.5: Fix a typo for "username map script" 2021-11-11 19:08:37 +00:00
validusers.xml Revert "docs-xml: Update documentation for removal of NIS support" 2022-06-09 21:45:28 +00:00
writeable.xml docs:smbdotconf: 'write ok' is a synonym of 'writeable' not of 'read only' 2015-07-31 01:55:31 +02:00
writelist.xml docs:smbdotconf: change type to cmdlist where needed. 2015-07-31 01:55:32 +02:00