s3-winbindd: Require SMB signing by default to disrupt MITM attacks with our DC
authorAndrew Bartlett <abartlet@samba.org>
Fri, 11 Oct 2013 02:10:29 +0000 (15:10 +1300)
committerAndrew Bartlett <abartlet@samba.org>
Sun, 28 Sep 2014 04:25:55 +0000 (06:25 +0200)
commita59b00dc91673f16be2fe84ddd7156e28b8080a7
tree4194ae3cb5cb294945d2746844b0e3ccf8f97b2e
parent775d1f8c41407617cc112ae48e9e22fcae0c82e6
s3-winbindd: Require SMB signing by default to disrupt MITM attacks with our DC

This makes it much harder to impersonate the DC, but allows this to be
turned off or returned to IF_REQUIRED with a simple change to the
'client signing' smb.conf parameter.

Andrew Bartlett

Signed-off-by: Andrew Bartlett <abartlet@samba.org>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
Autobuild-User(master): Andrew Bartlett <abartlet@samba.org>
Autobuild-Date(master): Sun Sep 28 06:25:55 CEST 2014 on sn-devel-104
source3/winbindd/winbindd_cm.c