CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: support "server require schannel...
authorGünther Deschner <gd@samba.org>
Thu, 17 Sep 2020 12:23:16 +0000 (14:23 +0200)
committerStefan Metzmacher <metze@samba.org>
Fri, 18 Sep 2020 12:48:39 +0000 (12:48 +0000)
commitb74017d2dd15006f4bec899aa38191a3b44800e4
treec44bd386ab8838be7e3107dbd3a230db36fdf64f
parent9ef5b63e7a169154401e58f7a29ed25443e5318f
CVE-2020-1472(ZeroLogon): s3:rpc_server/netlogon: support "server require schannel:WORKSTATION$ = no"

This allows to add expections for individual workstations, when using "server schannel = yes".
"server schannel = auto" is very insecure and will be removed soon.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=14497

Pair-Programmed-With: Stefan Metzmacher <metze@samba.org>

Signed-off-by: Günther Deschner <gd@samba.org>
Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Gary Lockyer <gary@catalyst.net.nz>
source3/rpc_server/netlogon/srv_netlog_nt.c