[cifs-protocol] KB5037754: How to manage PAC Validation changes related

abartlet at samba.org abartlet at samba.org
Tue Apr 9 23:53:50 UTC 2024


to CVE-2024-26248 and CVE-2024-29056
From: Andrew Bartlett <abartlet at samba.org>
To: Interoperability Documentation Help <dochelp at microsoft.com>
Cc: cifs-protocol mailing list <cifs-protocol at lists.samba.org>
Date: Wed, 10 Apr 2024 11:53:47 +1200
Content-Type: multipart/alternative; boundary="=-8y01DIddY9jBTc/TcbsU"
User-Agent: Evolution 3.36.5-0ubuntu1 
MIME-Version: 1.0


--=-8y01DIddY9jBTc/TcbsU
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit

(resend with correct subject)
Kia Ora Dochelp,
Recently I saw "KB5037754: How to manage PAC Validation changes
relatedto CVE-2024-26248 and CVE-2024-29056" was published. 
Can I have a pointer to the new NETLOGON behaviour and the
newstructures for the SamLogon PAC validation, and the new
requiredbehaviours so a Samba AD DC can handle this?
I don't see any errata that looks relevant yet.
Thanks,
Andrew Bartlett
-- 
Andrew Bartlett (he/him)       https://samba.org/~abartlet/
Samba Team Member (since 2001) https://samba.org
Samba Team Lead                https://catalyst.net.nz/services/samba
Catalyst.Net Ltd


Proudly developing Samba for Catalyst.Net Ltd - a Catalyst IT group
company

Samba Development and Support: https://catalyst.net.nz/services/samba

Catalyst IT - Expert Open Source Solutions




--=-8y01DIddY9jBTc/TcbsU
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html dir=3D"ltr"><head></head><body style=3D"text-align:left; direction:lt=
r;"><pre>(resend with correct subject)</pre><pre><br></pre><pre>Kia Ora Doc=
help,</pre><pre><br></pre><pre>Recently I saw "KB5037754: How to manage PAC=
 Validation changes related</pre><pre>to CVE-2024-26248 and CVE-2024-29056"=
 was published. </pre><pre><br></pre><pre>Can I have a pointer to the new N=
ETLOGON behaviour and the new</pre><pre>structures for the SamLogon PAC val=
idation, and the new required</pre><pre>behaviours so a Samba AD DC can han=
dle this?</pre><pre><br></pre><pre>I don't see any errata that looks releva=
nt yet.</pre><pre><br></pre><pre>Thanks,</pre><pre><br></pre><pre>Andrew Ba=
rtlett</pre><div><span><pre>-- <br></pre><div style=3D"width: 71ch;">Andrew=
 Bartlett (he/him)       <a href=3D"http=
s://samba.org/~abartlet/">https://samba.org/~abartlet/</a></div><div style=
=3D"width: 71ch;" data-evo-signature-plain-text-mode=3D"">Samba Team Member=
 (since 2001) <a href=3D"https://samba.org">https://samba.org</a></div><div=
 style=3D"width: 71ch;" data-evo-signature-plain-text-mode=3D"">Samba Team =
Lead                <a href=3D"http=
s://catalyst.net.nz/services/samba">https://catalyst.net.nz/services/samba<=
/a></div><div style=3D"width: 71ch;" data-evo-signature-plain-text-mode=3D"=
"><span style=3D"font-size: 17.333334px;">Catalyst.Net Ltd</span></div><div=
 style=3D"width: 71ch;" data-evo-signature-plain-text-mode=3D""><span style=
=3D"font-size: 17.333334px;"><br></span></div><div style=3D"width: 71ch;" d=
ata-evo-signature-plain-text-mode=3D"">Proudly developing Samba for Catalys=
t.Net Ltd - a Catalyst IT group company</div><div style=3D"width: 71ch;" da=
ta-evo-signature-plain-text-mode=3D""><br></div><div style=3D"width: 71ch;"=
 data-evo-signature-plain-text-mode=3D"">Samba Development and Support: <a =
href=3D"https://catalyst.net.nz/services/samba">https://catalyst.net.nz/ser=
vices/samba</a></div><div style=3D"width: 71ch;" data-evo-signature-plain-t=
ext-mode=3D""><br></div><div style=3D"width: 71ch;" data-evo-signature-plai=
n-text-mode=3D"">Catalyst IT - Expert Open Source Solutions</div><div style=
=3D"width: 71ch;" data-evo-signature-plain-text-mode=3D""><br></div><div st=
yle=3D"width: 71ch;" data-evo-signature-plain-text-mode=3D""><br></div></sp=
an></div></body></html>

--=-8y01DIddY9jBTc/TcbsU--




More information about the cifs-protocol mailing list