[Bug 1576799] Re: Regression: 2:4.3.8+dfsg-0ubuntu0.14.04.2 Failed to Issue the StartTLS instruction

Andreas Hasenack andreas at canonical.com
Wed Dec 13 11:48:25 UTC 2017


In particular, one of the fixes introduced in samba 4.3.7 was to
properly check certificates, as @mdeslaur said in comment #2:

"o  CVE-2016-2113 (Missing TLS certificate validation)"

So I would ask you to double check your certificates and chain to make
sure all is correct in that front, as samba would have skipped some
validation checks before.

** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-2113

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to samba in Ubuntu.
https://bugs.launchpad.net/bugs/1576799

Title:
  Regression: 2:4.3.8+dfsg-0ubuntu0.14.04.2 Failed to Issue the StartTLS
  instruction

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1576799/+subscriptions



More information about the Ubuntu-server-bugs mailing list