From: Samuel Cabrero Date: Thu, 22 Dec 2022 15:46:15 +0000 (+0100) Subject: CVE-2022-38023 selftest:Samba3: avoid global 'server schannel = auto' X-Git-Url: http://git.samba.org/?a=commitdiff_plain;h=6d31e359fbfbb2d635c837184551bdd513e16a22;p=metze%2Fsamba%2Fwip.git CVE-2022-38023 selftest:Samba3: avoid global 'server schannel = auto' Instead of using the generic deprecated option use the specific server require schannel:COMPUTERACCOUNT = no in order to allow legacy tests for pass. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15240 Signed-off-by: Samuel Cabrero Reviewed-by: Andreas Schneider (cherry picked from commit 3cd18690f83d2f85e847fc703ac127b4b04189fc) --- diff --git a/selftest/target/Samba3.pm b/selftest/target/Samba3.pm index 226cab316d29..f98d60442bb7 100755 --- a/selftest/target/Samba3.pm +++ b/selftest/target/Samba3.pm @@ -272,9 +272,23 @@ sub setup_nt4_dc lanman auth = yes ntlm auth = yes raw NTLMv2 auth = yes - server schannel = auto rpc start on demand helpers = false + CVE_2020_1472:warn_about_unused_debug_level = 3 + server require schannel:schannel0\$ = no + server require schannel:schannel1\$ = no + server require schannel:schannel2\$ = no + server require schannel:schannel3\$ = no + server require schannel:schannel4\$ = no + server require schannel:schannel5\$ = no + server require schannel:schannel6\$ = no + server require schannel:schannel7\$ = no + server require schannel:schannel8\$ = no + server require schannel:schannel9\$ = no + server require schannel:schannel10\$ = no + server require schannel:schannel11\$ = no + server require schannel:torturetest\$ = no + vfs_default:VFS_OPEN_HOW_RESOLVE_NO_SYMLINKS = no fss: sequence timeout = 1