Bug#820983: /usr/share/doc/samba/NEWS.Debian.gz: "smb signing" is an "unknown parameter"

2016-04-14 Thread Andrew Bartlett
On Thu, 2016-04-14 at 10:57 +0100, Roger Lynn wrote:
> Package: samba
> Version: 2:4.2.10+dfsg-0+deb8u1
> Severity: normal
> File: /usr/share/doc/samba/NEWS.Debian.gz
> 
> Hi,
> 
> The NEWS file states:
> 
> Finally, two important configuration options should be
> considered,
> that we were unable to silently change defaults for:
> - smb signing = required
> - ntlm auth = no
> 
> However smb signing is not a recognised parameter:
> 
> .../lib/param/loadparm.c:743(lpcfg_map_parameter)
>   Unknown parameter encountered: "smb signing"
> 
> Searching through SMB.CONF(5), it appears the intended parameter is:
> 
> client signing = mandatory
> 
> Is this correct? According to the NEWS file this option has security
> implications, so should be considered important.

Sadly time restrictions and I think a small miscommunication meant we
didn't get the latest version of the NEWS entry into the secuirty
release.  See here for a better set of text:

https://anonscm.debian.org/cgit/pkg-samba/samba.git/commit/?h=stable
-update&id=cbcad2a543a28926ee712cf299dbdc03da351cb0

Sorry about that.  I'm not sure we can fix this with a new package, but
I'll ask. 

Andrew Bartlett

-- 
Andrew Bartlett   http://samba.org/~abartlet/
Authentication Developer, Samba Team  http://samba.org
Samba Developer, Catalyst IT  http://catalyst.net.nz/services/samba



Bug#820983: /usr/share/doc/samba/NEWS.Debian.gz: "smb signing" is an "unknown parameter"

2016-04-14 Thread Roger Lynn
Package: samba
Version: 2:4.2.10+dfsg-0+deb8u1
Severity: normal
File: /usr/share/doc/samba/NEWS.Debian.gz

Hi,

The NEWS file states:

Finally, two important configuration options should be considered,
that we were unable to silently change defaults for:
- smb signing = required
- ntlm auth = no

However smb signing is not a recognised parameter:

.../lib/param/loadparm.c:743(lpcfg_map_parameter)
  Unknown parameter encountered: "smb signing"

Searching through SMB.CONF(5), it appears the intended parameter is:

client signing = mandatory

Is this correct? According to the NEWS file this option has security
implications, so should be considered important.

Thanks,

Roger


-- System Information:
Debian Release: 8.4
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'proposed-updates'), (500, 
'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.16.0-4-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages samba depends on:
ii  adduser  3.113+nmu3
ii  dpkg 1.17.26
ii  libacl1  2.2.52-2
ii  libattr1 1:2.4.47-2
ii  libbsd0  0.7.0-2
ii  libc62.19-18+deb8u4
ii  libcups2 1.7.5-11+deb8u1
ii  libhdb9-heimdal [heimdal-hdb-api-8]  1.6~rc2+dfsg-9
ii  libldap-2.4-22.4.40+dfsg-1+deb8u2
ii  libldb1  2:1.1.20-0+deb8u1
ii  libpam-modules   1.1.8-3.1+deb8u1+b1
ii  libpam-runtime   1.1.8-3.1+deb8u1
ii  libpopt0 1.16-10
ii  libpython2.7 2.7.9-2
ii  libtalloc2   2.1.2-0+deb8u1
ii  libtdb1  1.3.6-0+deb8u1
ii  libtevent0   0.9.25-0+deb8u1
ii  libwbclient0 2:4.2.10+dfsg-0+deb8u1
ii  lsb-base 4.1+Debian13+nmu1
ii  multiarch-support2.19-18+deb8u4
ii  procps   2:3.3.9-9
ii  python   2.7.9-1
ii  python-dnspython 1.12.0-1
ii  python-ntdb  1.0-5
ii  python-samba 2:4.2.10+dfsg-0+deb8u1
pn  python2.7:any
ii  samba-common 2:4.2.10+dfsg-0+deb8u1
ii  samba-common-bin 2:4.2.10+dfsg-0+deb8u1
ii  samba-dsdb-modules   2:4.2.10+dfsg-0+deb8u1
ii  samba-libs   2:4.2.10+dfsg-0+deb8u1
ii  tdb-tools1.3.6-0+deb8u1
ii  update-inetd 4.43

Versions of packages samba recommends:
ii  attr   1:2.4.47-2
ii  logrotate  3.8.7-1+b1
ii  samba-vfs-modules  2:4.2.10+dfsg-0+deb8u1

Versions of packages samba suggests:
pn  bind9  
pn  bind9utils 
pn  ctdb   
pn  ldb-tools  
ii  ntp1:4.2.6.p5+dfsg-7+deb8u1
pn  smbldap-tools  
pn  winbind

-- debconf information:
* samba/run_mode: daemons
  samba-common/title: