diff options
author | Andreas Schneider <asn@samba.org> | 2019-02-05 16:08:46 +0100 |
---|---|---|
committer | David Disseldorp <ddiss@samba.org> | 2019-02-07 17:23:18 +0100 |
commit | 3e25d4d55f85be3323861b9a2f59626246b57182 (patch) | |
tree | 1b4675ef9a5ad87f11f4f25b29d6a4f7ded8efea /docs-xml/smbdotconf | |
parent | f132c3767efd4197ae32a7114a7b91b55759adb4 (diff) | |
download | samba-3e25d4d55f85be3323861b9a2f59626246b57182.tar.gz |
docs-xml: Update documentation for 'restrict anonymous' option
Signed-off-by: Andreas Schneider <asn@samba.org>
Reviewed-by: Rowland Penny <rpenny@samba.org>
Reviewed-by: David Disseldorp <ddiss@samba.org>
Diffstat (limited to 'docs-xml/smbdotconf')
-rw-r--r-- | docs-xml/smbdotconf/security/restrictanonymous.xml | 45 |
1 files changed, 23 insertions, 22 deletions
diff --git a/docs-xml/smbdotconf/security/restrictanonymous.xml b/docs-xml/smbdotconf/security/restrictanonymous.xml index 78cafd21d55..06abe7b2bf7 100644 --- a/docs-xml/smbdotconf/security/restrictanonymous.xml +++ b/docs-xml/smbdotconf/security/restrictanonymous.xml @@ -3,34 +3,35 @@ context="G" xmlns:samba="http://www.samba.org/samba/DTD/samba-doc"> <description> - <para>The setting of this parameter determines whether user and - group list information is returned for an anonymous connection. - and mirrors the effects of the -<programlisting> -HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ - Control\LSA\RestrictAnonymous -</programlisting> - registry key in Windows 2000 and Windows NT. When set to 0, user - and group list information is returned to anyone who asks. When set - to 1, only an authenticated user can retrieve user and - group list information. For the value 2, supported by - Windows 2000/XP and Samba, no anonymous connections are allowed at - all. This can break third party and Microsoft - applications which expect to be allowed to perform - operations anonymously.</para> + <para> + The setting of this parameter determines whether SAMR and LSA + DCERPC services can be accessed anonymously. This corresponds + to the following Windows Server registry options: + </para> + + <programlisting> + HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous + </programlisting> + + <para> + The option also affects the browse option which is required by + legacy clients which rely on Netbios browsing. While modern + Windows version should be fine with restricting the access + there could still be applications relying on anonymous access. + </para> <para> - The security advantage of using restrict anonymous = 1 is dubious, - as user and group list information can be obtained using other - means. + Setting <smbconfoption name="restrict anonymous">1</smbconfoption> + will disable anonymous SAMR access. </para> - <note> <para> - The security advantage of using restrict anonymous = 2 is removed - by setting <smbconfoption name="guest ok">yes</smbconfoption> on any share. + Setting <smbconfoption name="restrict anonymous">2</smbconfoption> + will, in addition to restricting SAMR access, disallow anonymous + connections to the IPC$ share in general. + Setting <smbconfoption name="guest ok">yes</smbconfoption> on any share + will remove the security advantage. </para> - </note> </description> <value type="default">0</value> |