Corrado Ravinetto
2023-Mar-30 15:09 UTC
[Samba] R: R: R: upgrade from 4.17 to samba 4.18.1
My old dc it was on samba 4.17.4 and in my network i have many old pc with xp os -----Messaggio originale----- Da: samba <samba-bounces at lists.samba.org> Per conto di Rowland Penny via samba Inviato: gioved? 30 marzo 2023 15:53 A: samba at lists.samba.org Cc: Rowland Penny <rpenny at samba.org> Oggetto: Re: [Samba] R: R: upgrade from 4.17 to samba 4.18.1 On 30/03/2023 14:41, Christian Naumer via samba wrote:> Am Donnerstag, dem 30.03.2023 um 14:03 +0100 schrieb Rowland Penny via samba: >> >> >> On 30/03/2023 13:56, Corrado Ravinetto via samba wrote: >>> Ok, i added more than 50 rows like server reject md5 ecc.ecc.ecc. >>> Now logs are clean, but, before upgrade this not happened >>> >>> >> >> Which is why I said it was a bit weird. >> >> The CVE fixes went into Samba 4.16.8 and you upgraded from 4.17.x, so >> I would have expected that CVE fix to have been in your 4.17 version >> and for you to have had the lines in your log from then. > > > Hi Rowland, correct but also 4.17.4 was released with this fix. Maybe > the upgrade was from an earlier version?Corrado never actually mentioned what 4.17.x he upgraded from, but you are correct the CVE fix went into 4.15.13, 4.16.8 and 4.17.4 , Thanks for pointing that out, I should have checked better.> > What is more interesting is that he did not see any effect (something > not working) only the log entries. Not that he just opened that > security whole again by removing the errors in the log.He possibly has, which is why I also said: Then see if you can upgrade ARRQUADRO_2_16 to use a better cipher. If he could get the computer to use a better cipher, he then wouldn't need the line in smb.conf From the sound of it, he has some very old computers in his domain. Rowland -- To unsubscribe from this list go to the following URL and read the instructions: https://lists.samba.org/mailman/options/samba Corrado Ravinetto Sistemi informativi corrado.ravinetto at lanificiocerruti.com <mailto:corrado.ravinetto at lanificiocerruti.com> T: +39 015 3591283 [Lanificio F.lli CERRUTI] Lanificio F.lli Cerruti S.p.A. Via Cernaia 40, 13900 - Biella (BI) Italy www.lanificiocerruti.com <http://www.lanificiocerruti.com/> [Twitter] <https://twitter.com/Lan_Cerruti> [Facebook] <https://www.facebook.com/LanificioCerruti> [Instagram] <https://www.instagram.com/lanificiocerruti/> Rispetta l'ambiente, non stampare questa mail se non necessario Respect the environment, don't print unless necessary [Unesco]
On 30/03/2023 16:09, Corrado Ravinetto via samba wrote:> My old dc it was on samba 4.17.4 and in my network i have many old pc with xp os >Windows XP went EOL in 2014 (if I remember correctly) and unless you are one of those people that run it on an embedded computer in something like a CNC machine, you really should be upgrading to a supported Windows version. When Samba 5 does come out, it will remove SMBv1 (I am assured this will happen) and then your XP clients will not work. Better to be ahead of the game. Rowland