[Samba] Samba, AD and devices compatibility...

Marco Gaiarin gaio at sv.lnf.it
Fri May 11 07:58:11 UTC 2018


Mandi! Andrew Bartlett via samba
  In chel di` si favelave...

> > There's some way to ''tight'' that configuration , eg permit 'ldap server require strong auth =
> > no' only by some hosts?
> > Or some other smb.conf options that i've missed?

> Nothing at this stage.

Ok.


> The issue is that they need to do fully signed or sealed Kerberos SASL. 

Sorry, but i've really a bit of confusion in this field... You forgot a
'not' somwhere in this sentence? ;-)

I've understood that 'sign or seal' mean SASL over TLS/SSL, and my
printer suport only SASL, so it is not 'sign and sealed'...


> I agree that a per-IP or per-client whitelist would be a good idea. 

I suppose that a trick like:

	include = /etc/samba/smb.conf.%I

does not work for LDAP, but only for SMB part...

-- 
dott. Marco Gaiarin				        GNUPG Key ID: 240A3D66
  Associazione ``La Nostra Famiglia''          http://www.lanostrafamiglia.it/
  Polo FVG   -   Via della Bontà, 7 - 33078   -   San Vito al Tagliamento (PN)
  marco.gaiarin(at)lanostrafamiglia.it   t +39-0434-842711   f +39-0434-842797

		Dona il 5 PER MILLE a LA NOSTRA FAMIGLIA!
      http://www.lanostrafamiglia.it/index.php/it/sostienici/5x1000
	(cf 00307430132, categoria ONLUS oppure RICERCA SANITARIA)



More information about the samba mailing list