about wide links and unix extensions

Volker Lendecke Volker.Lendecke at SerNet.DE
Thu Feb 11 06:02:03 MST 2010


On Thu, Feb 11, 2010 at 12:45:08PM +0200, Adrian Buciuman wrote:
> I suggest that a new option is added to samba, to allow both wide
> links and unix extensions to coexist.  Otherwise, you may break
> existing, working setups for which there is no security concern in
> having them both on.

We will end up with another "0-day exploit" report if we do
that, and I don't know if I am happy asking for such a
thing...

I do see your point, we also have other options that make
your setup completely insecure like "admin users = @users"
or so, but for this one we have been bitten publically.
That's a difficult choice to make unfortunately.

Volker
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 197 bytes
Desc: Digital signature
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20100211/f9793f27/attachment.pgp>


More information about the samba-technical mailing list