CVE-2016-2113: selftest: use "tls verify peer = no_check"
authorStefan Metzmacher <metze@samba.org>
Sat, 26 Mar 2016 07:38:46 +0000 (08:38 +0100)
committerStefan Metzmacher <metze@samba.org>
Tue, 12 Apr 2016 17:25:25 +0000 (19:25 +0200)
Individual tests will check the more secure values.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=11752

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Alexander Bokovoy <ab@samba.org>
selftest/selftest.pl
selftest/target/Samba4.pm

index fa2f4cd903aa6053b9a1435add4b4359b032bdc1..ff5f27d08555c5177721ab504e63daa615b1efd6 100755 (executable)
@@ -594,6 +594,7 @@ sub write_clientconf($$$)
         winbind separator = /
        tls cafile = ${cacert}
        tls crlfile = ${cacrl_pem}
         winbind separator = /
        tls cafile = ${cacert}
        tls crlfile = ${cacrl_pem}
+       tls verify peer = no_check
 ";
        close(CF);
 }
 ";
        close(CF);
 }
index 14fddcfb83f410cc83927594f40889dda2ff5d48..eddcfa6cd52a2e0930295703180d5b5b0673a232 100755 (executable)
@@ -538,6 +538,7 @@ sub provision_raw_step1($$)
        interfaces = $ctx->{interfaces}
        tls dh params file = $ctx->{tlsdir}/dhparms.pem
        tls crlfile = ${crlfile}
        interfaces = $ctx->{interfaces}
        tls dh params file = $ctx->{tlsdir}/dhparms.pem
        tls crlfile = ${crlfile}
+       tls verify peer = no_check
        panic action = $RealBin/gdb_backtrace \%d
        wins support = yes
        server role = $ctx->{server_role}
        panic action = $RealBin/gdb_backtrace \%d
        wins support = yes
        server role = $ctx->{server_role}