Bug 1413484
Summary: | Unable to connect windows server 2012 servers to samba-3.6.23-36 with out disabling SMB signing | ||||||
---|---|---|---|---|---|---|---|
Product: | Red Hat Enterprise Linux 6 | Reporter: | fjayalat | ||||
Component: | samba | Assignee: | Andreas Schneider <asn> | ||||
Status: | CLOSED ERRATA | QA Contact: | qe-baseos-daemons | ||||
Severity: | high | Docs Contact: | Lucie Vařáková <lmanasko> | ||||
Priority: | high | ||||||
Version: | 6.8 | CC: | amitkuma, asn, cww, fhanzelk, gdeschner, jarrpa, lmanasko, rhack | ||||
Target Milestone: | rc | ||||||
Target Release: | --- | ||||||
Hardware: | x86_64 | ||||||
OS: | Linux | ||||||
Whiteboard: | |||||||
Fixed In Version: | samba-3.6.23-47.el6 | Doc Type: | Bug Fix | ||||
Doc Text: |
Connecting with SMB signing now enabled
Previously, the badlock security flaw fixes caused a regression. This prevented users from connecting from Windows server 2012 servers to the Samba suite without disabling the server message block (SMB) signing. With this update, it is possible to connect with SMB signing enabled and the users of Windows server 2012 can connect to samba without problems.
|
Story Points: | --- | ||||
Clone Of: | Environment: | ||||||
Last Closed: | 2018-06-19 05:08:55 UTC | Type: | Bug | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | |||||||
Bug Blocks: | 1461138, 1504542 | ||||||
Attachments: |
|
Description
fjayalat
2017-01-16 06:09:24 UTC
Created attachment 1241114 [details]
Error
*** Bug 1495448 has been marked as a duplicate of this bug. *** = Reproducer = == smb.conf == [global] map to guest = Bad user [testshare] path = /foo guest ok = yes == smbclient == smbclient //SERVER/testshare -U% --signing=required Looking at the log from comment #16, smbd failed to start or update correctly. Or smbd was alredy running and the customer tried to start another instance. Hello ASN, Got update from customer after running test-packs: Freshly installed rhel6.4 [rhel-6.4-Have-test-pack-installed] Windows-7-Client RequireSecuritySignature = 0 <--------Access share------------ Can access[ok] RequireSecuritySignature = 1 <--------Access share------------ Cannot access[FAIL] The account is not authorized to log in from this station Thanks Amit Hello ASN, More testing on Client setup => [rhel-6.4-Have-test-pack-installed] Windows-2012-Client RequireSecuritySignature = 0 <--------Access share------------ Can access[ok] RequireSecuritySignature = 1 <--------Access share------------ Can access[ok] [rhel-6.4-Have-test-pack-installed] smbclient # smbclient //<ip>/share -U% --signing=required smb> Can access[ok] # smbclient //<ip>/share -U% --signing=auto smb> Can access[ok] Same behavior on samba4. Thanks Amit Please Ignore Comment#19: This is correct one: [rhel-6.4-Have-test-pack-installed] Windows-2012-Client RequireSecuritySignature = 0 <--------Access share------------ Can access[ok] RequireSecuritySignature = 1 ....Cannot Not test.... [rhel-6.4-Have-test-pack-installed] smbclient # smbclient //<ip>/share -U% --signing=required smb> Can access[ok] # smbclient //<ip>/share -U% --signing=auto smb> Can access[ok] [rhel-6.4-Have-test-pack-installed] Windows-7-Client RequireSecuritySignature = 0 <--------Access share------------ Can access[ok] RequireSecuritySignature = 1 <--------Access share------------ Cannot access[FAIL] The account is not authorized to log in from this station Thanks Amit Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHSA-2018:1860 |