[PATCH] Update 'restrict anonymous' in smb.conf.5 manpage

Andreas Schneider asn at samba.org
Wed Feb 6 16:22:51 UTC 2019


On Wednesday, February 6, 2019 5:11:17 PM CET Rowland Penny wrote:
> Setting <smbconfoption name="restrict anonymous">2</smbconfoption>
> will, in addition to restricting SAMR access, disallow anonymous connections
> to the IPC$ share in general.

Thanks, updated patch attached.

-- 
Andreas Schneider                      asn at samba.org
Samba Team                             www.samba.org
GPG-ID:     8DFF53E18F2ABC8D8F3C92237EE0FC4DCC014E3D
-------------- next part --------------
From bf91ee0a9727cc392583fe84ad069204be758515 Mon Sep 17 00:00:00 2001
From: Ralph Boehme <slow at samba.org>
Date: Tue, 5 Feb 2019 14:08:56 +0100
Subject: [PATCH 1/2] tldap: avoid more use after free errors
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

See the previous commit for an explanation. :)

Bug: https://bugzilla.samba.org/show_bug.cgi?id=13776

Signed-off-by: Ralph Boehme <slow at samba.org>
Reviewed-by: Volker Lendecke <vl at samba.org>

Autobuild-User(master): Ralph Böhme <slow at samba.org>
Autobuild-Date(master): Wed Feb  6 10:19:12 CET 2019 on sn-devel-144
---
 source3/lib/tldap_util.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/source3/lib/tldap_util.c b/source3/lib/tldap_util.c
index 508c6c02f80..54a9eb30bbe 100644
--- a/source3/lib/tldap_util.c
+++ b/source3/lib/tldap_util.c
@@ -457,7 +457,6 @@ static void tldap_fetch_rootdse_done(struct tevent_req *subreq)
 
 	rc = tldap_search_recv(subreq, state, &msg);
 	if (tevent_req_ldap_error(req, rc)) {
-		TALLOC_FREE(subreq);
 		return;
 	}
 
@@ -739,7 +738,6 @@ static void tldap_search_paged_done(struct tevent_req *subreq)
 
 	rc = tldap_search_recv(subreq, state, &state->result);
 	if (tevent_req_ldap_error(req, rc)) {
-		TALLOC_FREE(subreq);
 		return;
 	}
 
-- 
2.20.1


From d7d23dbaf1f4dd1b5e20573b9c297c7e6786ec91 Mon Sep 17 00:00:00 2001
From: Andreas Schneider <asn at samba.org>
Date: Tue, 5 Feb 2019 16:08:46 +0100
Subject: [PATCH 2/2] docs-xml: Update documentation for 'restrict anonymous'
 option

Signed-off-by: Andreas Schneider <asn at samba.org>
---
 .../smbdotconf/security/restrictanonymous.xml | 45 ++++++++++---------
 1 file changed, 23 insertions(+), 22 deletions(-)

diff --git a/docs-xml/smbdotconf/security/restrictanonymous.xml b/docs-xml/smbdotconf/security/restrictanonymous.xml
index 78cafd21d55..c5f0b809a2e 100644
--- a/docs-xml/smbdotconf/security/restrictanonymous.xml
+++ b/docs-xml/smbdotconf/security/restrictanonymous.xml
@@ -3,34 +3,35 @@
                  context="G"
                  xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">
 <description>
-    <para>The setting of this parameter determines whether user and
-    group list information is returned for an anonymous connection.
-    and mirrors the effects of the
-<programlisting>
-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
-           Control\LSA\RestrictAnonymous
-</programlisting>
-	registry key in Windows 2000 and Windows NT.  When set to 0, user
-	and group list information is returned to anyone who asks.  When set
-    to 1, only an authenticated user can retrieve user and
-    group list information.  For the value 2, supported by
-    Windows 2000/XP and Samba, no anonymous connections are allowed at
-    all.  This can break third party and Microsoft
-    applications which expect to be allowed to perform
-	operations anonymously.</para>
+	<para>
+		The setting of this parameter determines whether SAMR and LSA
+		DCERPC services can be accessed anonymously. This corresponds
+		to the following Windows Server registry options:
+	</para>
+
+	<programlisting>
+		HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous
+	</programlisting>
+
+	<para>
+		The option also affects the browse option which is required by
+		legacy clients which rely on Netbios browsing. While modern
+		Windows version should be fine with restricting the access
+		there could still be applications relying on anonymous access.
+	</para>
 
 	<para>
-    The security advantage of using restrict anonymous = 1 is dubious,
-    as user and group list information can be obtained using other
-	means.
+		Setting <smbconfoption name="restrict anonymous">1</smbconfoption>
+		will disable anonymous SAMR access.
 	</para>
 
-	<note>
 	<para>
-    The security advantage of using restrict anonymous = 2 is removed
-    by setting <smbconfoption name="guest ok">yes</smbconfoption> on any share.
+		Setting <smbconfoption name="restrict anonymous">2</smbconfoption>
+		will, in addition to restricting SAMR access, disallow anonymous
+		connections to the IPC$ share in general.
+		Setting <smbconfoption name="guest ok">yes</smbconfoption> on any share
+		will will remove the security advantage.
 	</para>
-	</note>
 </description>
 
 <value type="default">0</value>
-- 
2.20.1



More information about the samba-technical mailing list