From: Karolin Seeger Date: Tue, 30 Oct 2007 07:42:25 +0000 (+0000) Subject: Add manpage section for the new parameter client ldap sasl wrapping X-Git-Tag: samba-3.3.0pre1~1558 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=051bb7d548c67a467296abf8895fc156e9ecb4a2;p=thirdparty%2Fsamba.git Add manpage section for the new parameter client ldap sasl wrapping Karolin --- diff --git a/docs/smbdotconf/ldap/clientldapsaslwrapping.xml b/docs/smbdotconf/ldap/clientldapsaslwrapping.xml new file mode 100644 index 00000000000..0f85646866c --- /dev/null +++ b/docs/smbdotconf/ldap/clientldapsaslwrapping.xml @@ -0,0 +1,43 @@ + + + + The defines whether + ldap traffic will be signed or signed and encrypted (sealed). + Possible values are plain, sign + and seal. + + + + The values sign and seal + are only available if Samba has been compiled against a modern + OpenLDAP version (2.3.x or higher). + + + + This option is needed in the case of Domain Controllers enforcing + the usage of signed LDAP connections (e.g. Windows 2000 SP3 or higher). + LDAP sign and seal can be controlled with the registry key + "HKLM\System\CurrentControlSet\Services\NTDS\Parameters\LDAPServerIntegrity" + on the Windows server side. + + + + Depending on the used KRB5 library (MIT and older Heimdal versions) + it is possible that the message "integrity only" is not supported. + In this case, sign is just an alias for + seal. + + + + The default value is plain which is not irritable + to KRB5 clock skew errors. That implies synchronizing the time + with the KDC in the case of using sign or + seal. + + +plain + diff --git a/docs/smbdotconf/security/clientsigning.xml b/docs/smbdotconf/security/clientsigning.xml index 02a7ce38a92..bf37cbb8746 100644 --- a/docs/smbdotconf/security/clientsigning.xml +++ b/docs/smbdotconf/security/clientsigning.xml @@ -12,7 +12,8 @@ When set to auto, SMB signing is offered, but not enforced. When set to mandatory, SMB signing is required and if set - to disabled, SMB signing is not offered either. + to disabled, SMB signing is not offered either. + auto