[PATCH] cifs: connect: added option krb5mi which may allow package signing

Jeff Layton jlayton at samba.org
Wed Feb 26 13:26:34 MST 2014


On Wed, 26 Feb 2014 14:46:47 +0100
"Lorenz Bucher" <Lorenz.Bucher at gmx.de> wrote:

> Solves an issue with dfs where servers using package signing are
> mixed with servers which don't use package signing.
> 
> Signed-off-by: Lorenz Bucher <lorenz.bucher at gmx.de>
> ---
>  fs/cifs/connect.c |    3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/fs/cifs/connect.c b/fs/cifs/connect.c
> index 56c152d..9d06dd8 100644
> --- a/fs/cifs/connect.c
> +++ b/fs/cifs/connect.c
> @@ -1104,6 +1104,9 @@ cifs_parse_mount_options(const char *mountdata, const char *devname,
>                         if (!value || !*value) {
>                                 cERROR(1, "no security value specified");
>                                 continue;
> +                       } else if (strnicmp(value, "krb5mi", 6) == 0) {
> +                               vol->secFlg |= CIFSSEC_MAY_KRB5 | 
> +                                       CIFSSEC_MAY_SIGN;
>                         } else if (strnicmp(value, "krb5i", 5) == 0) {
>                                 vol->secFlg |= CIFSSEC_MAY_KRB5 |
>                                         CIFSSEC_MUST_SIGN;

This looks like it applies to a really old kernel. I think that problem
was what commit 0b7bc84000d71f3647ca33ab1bf5bd928535c846 was intended
to fix.

-- 
Jeff Layton <jlayton at samba.org>


More information about the samba-technical mailing list