[Bug 1576799] Re: Regression: 2:4.3.8+dfsg-0ubuntu0.14.04.2 Failed to Issue the StartTLS instruction
Andreas Hasenack
andreas at canonical.com
Wed Dec 13 11:48:25 UTC 2017
In particular, one of the fixes introduced in samba 4.3.7 was to
properly check certificates, as @mdeslaur said in comment #2:
"o CVE-2016-2113 (Missing TLS certificate validation)"
So I would ask you to double check your certificates and chain to make
sure all is correct in that front, as samba would have skipped some
validation checks before.
** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2016-2113
--
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to samba in Ubuntu.
https://bugs.launchpad.net/bugs/1576799
Title:
Regression: 2:4.3.8+dfsg-0ubuntu0.14.04.2 Failed to Issue the StartTLS
instruction
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1576799/+subscriptions
More information about the Ubuntu-server-bugs
mailing list