From: Samuel Cabrero Date: Thu, 22 Dec 2022 15:46:15 +0000 (+0100) Subject: CVE-2022-38023 selftest:Samba3: avoid global 'server schannel = auto' X-Git-Tag: talloc-2.4.0~57 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=3cd18690f83d2f85e847fc703ac127b4b04189fc;p=thirdparty%2Fsamba.git CVE-2022-38023 selftest:Samba3: avoid global 'server schannel = auto' Instead of using the generic deprecated option use the specific server require schannel:COMPUTERACCOUNT = no in order to allow legacy tests for pass. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15240 Signed-off-by: Samuel Cabrero Reviewed-by: Andreas Schneider --- diff --git a/selftest/target/Samba3.pm b/selftest/target/Samba3.pm index 917c2957b97..aee3460627f 100755 --- a/selftest/target/Samba3.pm +++ b/selftest/target/Samba3.pm @@ -272,9 +272,23 @@ sub setup_nt4_dc lanman auth = yes ntlm auth = yes raw NTLMv2 auth = yes - server schannel = auto rpc start on demand helpers = false + CVE_2020_1472:warn_about_unused_debug_level = 3 + server require schannel:schannel0\$ = no + server require schannel:schannel1\$ = no + server require schannel:schannel2\$ = no + server require schannel:schannel3\$ = no + server require schannel:schannel4\$ = no + server require schannel:schannel5\$ = no + server require schannel:schannel6\$ = no + server require schannel:schannel7\$ = no + server require schannel:schannel8\$ = no + server require schannel:schannel9\$ = no + server require schannel:schannel10\$ = no + server require schannel:schannel11\$ = no + server require schannel:torturetest\$ = no + vfs_default:VFS_OPEN_HOW_RESOLVE_NO_SYMLINKS = no fss: sequence timeout = 1