Skip to content
Commit 0603c96f authored by Steve French's avatar Steve French
Browse files

SMB: Validate negotiate (to protect against downgrade) even if signing off



As long as signing is supported (ie not a guest user connection) and
connection is SMB3 or SMB3.02, then validate negotiate (protect
against man in the middle downgrade attacks).  We had been doing this
only when signing was required, not when signing was just enabled,
but this more closely matches recommended SMB3 behavior and is
better security.  Suggested by Metze.

Signed-off-by: default avatarSteve French <smfrench@gmail.com>
Reviewed-by: default avatarJeremy Allison <jra@samba.org>
Acked-by: default avatarStefan Metzmacher <metze@samba.org>
Reviewed-by: default avatarRonnie Sahlberg <lsahlber@redhat.com>
CC: Stable <stable@vger.kernel.org>
parent f5c4ba81
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment