[Samba] Signing: partial(AES-128-CMAC)

cYuSeDfZfb cYuSeDfZfb cyusedfzfb at gmail.com
Thu May 11 09:48:57 UTC 2023


Wow that layout was seriously messed up. :-/

See here:
https://controlc.com/2c2775cc

On Thu, 11 May 2023 at 11:44, cYuSeDfZfb cYuSeDfZfb
<cyusedfzfb at gmail.com> wrote:
>
> Hi,
>
> Noticed in my smbstatus output:
>
> Samba version 4.17.5
> PID     Username     Group        Machine
>      Protocol Version  Encryption           Signing
> ----------------------------------------------------------------------------------------------------------------------------------------
> 2691    galera3      galera3      192.168.78.119
> (ipv4:192.168.78.119:49536) SMB3_11           AES-128-GCM
> partial(AES-128-CMAC)
>
> Service      pid     Machine       Connected at
> Encryption   Signing
> ---------------------------------------------------------------------------------------------
> IPC$         2691    192.168.78.119 Thu May 11 11:41:39 AM 2023 CEST
> AES-128-GCM  AES-128-CMAC
> galera3      2691    192.168.78.119 Thu May 11 11:41:39 AM 2023 CEST
> AES-128-GCM  AES-128-CMAC
>
>
> This is samba 4.17.5, and a pretty basic (security=user) smb.conf with
> just basics and only these security additions:
>
>     client signing = mandatory
>     server signing = mandatory
>     smb encrypt = mandatory
>
> Why is Signing only "partial"? Anything I can do to improve that?
>
> Thanks!



More information about the samba mailing list