]> git.ipfire.org Git - thirdparty/samba.git/commitdiff
CVE-2020-25719 CVE-2020-25717: selftest: remove "gensec:require_pac" settings
authorStefan Metzmacher <metze@samba.org>
Fri, 22 Oct 2021 14:20:36 +0000 (16:20 +0200)
committerJule Anger <janger@samba.org>
Tue, 9 Nov 2021 19:45:32 +0000 (19:45 +0000)
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14799
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14556
BUG: https://bugzilla.samba.org/show_bug.cgi?id=14561

[jsutton@samba.org Added knownfail entries]

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
selftest/knownfail.d/no-pac [new file with mode: 0644]
selftest/selftest.pl
selftest/target/Samba4.pm

diff --git a/selftest/knownfail.d/no-pac b/selftest/knownfail.d/no-pac
new file mode 100644 (file)
index 0000000..9723d58
--- /dev/null
@@ -0,0 +1,4 @@
+^samba.tests.krb5.test_ccache.samba.tests.krb5.test_ccache.CcacheTests.test_ccache_no_pac
+^samba.tests.krb5.test_ldap.samba.tests.krb5.test_ldap.LdapTests.test_ldap_no_pac
+^samba.tests.krb5.test_rpc.samba.tests.krb5.test_rpc.RpcTests.test_rpc_no_pac
+^samba.tests.krb5.test_smb.samba.tests.krb5.test_smb.SmbTests.test_smb_no_pac
index 9d4462323f5b76ceac8bbee47406d6f603facc24..75763ef3838a84a1b51c26ccfb8fa358f596f5a2 100755 (executable)
@@ -586,8 +586,6 @@ sub write_clientconf($$$)
        client min protocol = CORE
        log level = $client_loglevel
        torture:basedir = $clientdir
-#We don't want to pass our self-tests if the PAC code is wrong
-       gensec:require_pac = true
 #We don't want to run 'speed' tests for very long
         torture:timelimit = 1
         winbind separator = /
index 4b302aa19de5975d102014e167d60a7145d60df2..aafe183dcedf8e535556dd1f8df381626fb05a3b 100755 (executable)
@@ -785,8 +785,6 @@ sub provision_raw_step1($$)
        notify:inotify = false
        ldb:nosync = true
        ldap server require strong auth = yes
-#We don't want to pass our self-tests if the PAC code is wrong
-       gensec:require_pac = true
        log file = $ctx->{logdir}/log.\%m
        log level = $ctx->{server_loglevel}
        lanman auth = Yes