[Samba] PROPOSAL: Remove SWAT in Samba 4.1
Andrew Bartlett
abartlet at samba.org
Sun Feb 17 19:08:08 MST 2013
On Sun, 2013-02-17 at 20:52 -0500, Nico Kadel-Garcia wrote:
> On Sun, Feb 17, 2013 at 7:02 PM, Andrew Bartlett <abartlet at samba.org> wrote:
> > As most of you would have noticed, we have now had 3 CVE-nominated
> > security issues for SWAT in the past couple of years.
>
> Has "webmin" kept up to date with the latest structural changes in
> smb.conf? I'll admit that I've long preferred the "webmin" module
> structure over the dedicated add-on structures of "swat".
It seems webmin has much the same challenges, perhaps because it's a
package of a similar age. Or web security is just hard...
http://www.webmin.com/security.html
smb.conf hasn't changed structure in a long time, but we do add/remove
options each release. Neither is likely to do the AD DC stuff very well
right now.
Andrew Bartlett
--
Andrew Bartlett http://samba.org/~abartlet/
Authentication Developer, Samba Team http://samba.org
More information about the samba-technical
mailing list