[Samba] PROPOSAL: Remove SWAT in Samba 4.1

Andrew Bartlett abartlet at samba.org
Sun Feb 17 19:08:08 MST 2013


On Sun, 2013-02-17 at 20:52 -0500, Nico Kadel-Garcia wrote:
> On Sun, Feb 17, 2013 at 7:02 PM, Andrew Bartlett <abartlet at samba.org> wrote:
> > As most of you would have noticed, we have now had 3 CVE-nominated
> > security issues for SWAT in the past couple of years.
> 
> Has "webmin" kept up to date with the latest structural changes in
> smb.conf? I'll admit that I've long preferred the "webmin" module
> structure over the dedicated add-on structures of "swat".

It seems webmin has much the same challenges, perhaps because it's a
package of a similar age.  Or web security is just hard...
http://www.webmin.com/security.html

smb.conf hasn't changed structure in a long time, but we do add/remove
options each release.  Neither is likely to do the AD DC stuff very well
right now. 

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org




More information about the samba mailing list