[Samba] gnutls 3.7.2 in https://copr.fedorainfracloud.org/coprs/sergiomb/SambaAD/ ?
nkadel at gmail.com
Sat Oct 15 18:25:41 UTC 2022
On Fri, Oct 14, 2022 at 7:48 PM Kris Lou via samba
<samba at lists.samba.org> wrote:
> > 2022/01/23 20:31:10.008619, 3]
> > ../../lib/ldb-samba/ldb_wrap.c:332(ldb_wrap_connect) ldb_wrap open of
> > secrets.ldb [2022/01/23 20:31:10.011317, 0]
> > ../../source4/lib/tls/tls_tstream.c:1300(_tstream_tls_accept_send)
> > _tstream_tls_accept_send: TLS ../../source4/lib/tls/tls_tstream.c:1300 -
> > The request is invalid.. Failed to set default priorities
> I just encountered this with Tranquil.IT's 4.16.5 packages on CentOS 7 --
> which also includes compat-gnutls37. As previously mentioned, it seems to
> break TLS and thus LDAPS, and probably more. This was not an issue with
> Samba 4.15.x/compat-gnutls34.
These compatibility difficulties are why I've personally given up on
backporting current Samba releases to RHEL 7. Since RHEL 7 is on its
last legs, with maintenance support ended for ARM and Power platforms
ended, it doesn't seem like a wise place to invest the backporting
effort for system critical libraries like gnutls.
> After more digging  (among others), it appears that compat-gnutls37
> (both from the COPR  and Tranquil.IT) look for a systemwide config file
> that doesn't exist and isn't created by the package --
Interesting catch. As it is, I'm staring at a CentOS 8's copy of that
file, and seeng this:
lrwxrwxrwx. 1 root root 45 Sep 29 07:53 gnutls.config ->
[nkadel at nkadel-c8 back-ends]$ rpm -q -f gnutls.config
So inserting it in RHEL 7 would probably be best done with a teeny
accessory RPM and a file dependency, to deploy it along the
> Creating this file (with Johannes' defaults  ) seems to fix this issue.
> It'd be nice if this were deployed with the package, but considering that
> it seems to be a "system" config, there might be unintended consequences.
> (Perhaps using NORMAL?)
> # Johannes Engel version
> #SYSTEM = SECURE192:-VERS-ALL:+VERS-TLS1.2:+VERS-TLS1.3
> # Or set to NORMAL as a reasonable default?
> SYSTEM = NORMAL
> Hope this helps someone else with legacy systems ...
>  https://lists.samba.org/archive/samba/2020-December/233651.html
>  https://gnutls.org/manual/html_node/Priority-Strings.html
> Kris Lou
> klou at themusiclink.net
> To unsubscribe from this list go to the following URL and read the
> instructions: https://lists.samba.org/mailman/options/samba
More information about the samba