Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

[Samba] Samba 4 - disabling SSLv3 to mitigate POODLE effects

25 views
Skip to first unread message

Mario Pio Russo

unread,
Jul 8, 2015, 4:49:17 AM7/8/15
to

Good Day All

Sorry if this is a repeated email, but I need some information about how to
disable SSL on a Samba4.2.2 AD domain controller as the nessus scanner is
reporting the POODLE vulnerability and we are not allowed to have any of
that in our environment.

the nessus scan reports poodle vulnerability on all these ports:

443, 636, 3269

I had a look at previous posts but couldn't find a definitive answer

any help is highly appreciated.

Thank you
___________________________________________________________________________________________

Mario Pio Russo, System Admin SWG IT Services Dublin, Phone & FAX: +353 1
815 2236, eMail: mariop...@ie.ibm.com
IBM Ireland Product Distribution Limited registered in Ireland with number
92815. Registered Office: IBM House, Shelbourne Road, Ballsbridge, Dublin 4

(Embedded image moved to file: pic14574.gif)

Kelvin Yip

unread,
Jul 8, 2015, 5:13:37 AM7/8/15
to
I have file a bug and modified the source code to make samba4 do not use
SSLV3, but I am not able to make a patch to this.
https://bugzilla.samba.org/show_bug.cgi?id=11076
--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/options/samba

Mario Pio Russo

unread,
Jul 8, 2015, 10:02:43 AM7/8/15
to
Thanks Kelvin

I'm a bit confised tho, is this patch already avaiable? if yes, what is the
parameter that disable ssl into the smb.conf? Maybe the guys from
Enterprise samba have already included the patch into their releases so
it's just a maatter of enabling the flag.

I'm using sernet-samba-4.2.2

Thanks!
___________________________________________________________________________________________

Mario Pio Russo, System Admin SWG IT Services Dublin, Phone & FAX: +353 1
815 2236, eMail: mariop...@ie.ibm.com
IBM Ireland Product Distribution Limited registered in Ireland with number
92815. Registered Office: IBM House, Shelbourne Road, Ballsbridge, Dublin 4

(Embedded image moved to file: pic57151.gif)
0 new messages