Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

support security flaw feature fixes #21

Open
KlavsKlavsen opened this issue Jun 2, 2016 · 0 comments
Open

support security flaw feature fixes #21

KlavsKlavsen opened this issue Jun 2, 2016 · 0 comments

Comments

@KlavsKlavsen
Copy link

KlavsKlavsen commented Jun 2, 2016

Hi,

As listed here:
https://access.redhat.com/articles/2243351

There are several settings which should be enabled in samba by default - to ensure a secure samba setup.

I'll gladly make a PR - but wanted to hear how you wanted it implemented?

I was thinking these should just be part of args for samba class - with the below (safe) defaults:
server signing = mandatory
server min protocol = SMB2
tls verify peer = as_strict_as_possible
ldap server require strong auth = yes
raw NTLMv2 auth = no

several of these options are new - in centos atleast - due them being backported to fix security issues. So it might give issues with older samba servers (which will then be insecure)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant