CVE-2022-38023 s3:rpc_server/netlogon: Check for global "server schannel require...
authorSamuel Cabrero <scabrero@suse.de>
Thu, 22 Dec 2022 10:05:33 +0000 (11:05 +0100)
committerAndreas Schneider <asn@cryptomilk.org>
Mon, 9 Jan 2023 14:23:36 +0000 (14:23 +0000)
commita0b97e262318dc56fe663da89b0ee3172b2e7848
tree46802adc3f47c5466afa351f2de49cbffe64669a
parentca07f4340ce58a7e940a1123888b7409176412f7
CVE-2022-38023 s3:rpc_server/netlogon: Check for global "server schannel require seal"

By default we'll now require schannel connections with privacy/sealing/encryption.

But we allow exceptions for specific computer/trust accounts.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15240

Signed-off-by: Samuel Cabrero <scabrero@samba.org>
Reviewed-by: Andreas Schneider <asn@samba.org>
source3/rpc_server/netlogon/srv_netlog_nt.c