summaryrefslogtreecommitdiff
path: root/docs-xml
diff options
context:
space:
mode:
authorAndreas Schneider <asn@samba.org>2019-02-05 16:08:46 +0100
committerDavid Disseldorp <ddiss@samba.org>2019-02-07 17:23:18 +0100
commit3e25d4d55f85be3323861b9a2f59626246b57182 (patch)
tree1b4675ef9a5ad87f11f4f25b29d6a4f7ded8efea /docs-xml
parentf132c3767efd4197ae32a7114a7b91b55759adb4 (diff)
downloadsamba-3e25d4d55f85be3323861b9a2f59626246b57182.tar.gz
docs-xml: Update documentation for 'restrict anonymous' option
Signed-off-by: Andreas Schneider <asn@samba.org> Reviewed-by: Rowland Penny <rpenny@samba.org> Reviewed-by: David Disseldorp <ddiss@samba.org>
Diffstat (limited to 'docs-xml')
-rw-r--r--docs-xml/smbdotconf/security/restrictanonymous.xml45
1 files changed, 23 insertions, 22 deletions
diff --git a/docs-xml/smbdotconf/security/restrictanonymous.xml b/docs-xml/smbdotconf/security/restrictanonymous.xml
index 78cafd21d55..06abe7b2bf7 100644
--- a/docs-xml/smbdotconf/security/restrictanonymous.xml
+++ b/docs-xml/smbdotconf/security/restrictanonymous.xml
@@ -3,34 +3,35 @@
context="G"
xmlns:samba="http://www.samba.org/samba/DTD/samba-doc">
<description>
- <para>The setting of this parameter determines whether user and
- group list information is returned for an anonymous connection.
- and mirrors the effects of the
-<programlisting>
-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
- Control\LSA\RestrictAnonymous
-</programlisting>
- registry key in Windows 2000 and Windows NT. When set to 0, user
- and group list information is returned to anyone who asks. When set
- to 1, only an authenticated user can retrieve user and
- group list information. For the value 2, supported by
- Windows 2000/XP and Samba, no anonymous connections are allowed at
- all. This can break third party and Microsoft
- applications which expect to be allowed to perform
- operations anonymously.</para>
+ <para>
+ The setting of this parameter determines whether SAMR and LSA
+ DCERPC services can be accessed anonymously. This corresponds
+ to the following Windows Server registry options:
+ </para>
+
+ <programlisting>
+ HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\RestrictAnonymous
+ </programlisting>
+
+ <para>
+ The option also affects the browse option which is required by
+ legacy clients which rely on Netbios browsing. While modern
+ Windows version should be fine with restricting the access
+ there could still be applications relying on anonymous access.
+ </para>
<para>
- The security advantage of using restrict anonymous = 1 is dubious,
- as user and group list information can be obtained using other
- means.
+ Setting <smbconfoption name="restrict anonymous">1</smbconfoption>
+ will disable anonymous SAMR access.
</para>
- <note>
<para>
- The security advantage of using restrict anonymous = 2 is removed
- by setting <smbconfoption name="guest ok">yes</smbconfoption> on any share.
+ Setting <smbconfoption name="restrict anonymous">2</smbconfoption>
+ will, in addition to restricting SAMR access, disallow anonymous
+ connections to the IPC$ share in general.
+ Setting <smbconfoption name="guest ok">yes</smbconfoption> on any share
+ will remove the security advantage.
</para>
- </note>
</description>
<value type="default">0</value>