encrypt the tcon itself if seal requested on mount and set encryption support for 3.11 properly

Steve French smfrench at gmail.com
Sat Apr 21 04:55:41 UTC 2018


On Fri, Apr 20, 2018 at 7:14 PM, Pavel Shilovsky <piastryyy at gmail.com> wrote:
> Looks good. Please also fix the encryption negotiate context:

 Fixed. Disabled AES-128GCM.  See attached.

Seems to work ok to Windows 3.11 now, and SMB3 tconx is also now
encrypted if "seal" chosen on mount - tried it to Windows 2016 and to
Samba 4.7

Main remaining problem that I see is smb3.11 reconnect (it looks like
we are clearing the hash - but must be missing something)
-- 
Thanks,

Steve
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-SMB3-Fix-3.11-encryption-to-Windows-and-handle-encry.patch
Type: text/x-patch
Size: 3409 bytes
Desc: not available
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20180420/87d04aa4/0001-SMB3-Fix-3.11-encryption-to-Windows-and-handle-encry.bin>


More information about the samba-technical mailing list