diff options
author | Jeremy Allison <jra@samba.org> | 2015-03-19 13:09:21 -0700 |
---|---|---|
committer | Jeremy Allison <jra@samba.org> | 2015-03-25 22:21:13 +0100 |
commit | c9299bd6a4e86dbec10ab7741056f331a18c44a0 (patch) | |
tree | f4582ff7eb9ae17b4e232a5b50030c909a81ace6 /docs-xml | |
parent | caaf89e899c2a3926fb9e54d1c86f1a9cd5d7618 (diff) | |
download | samba-c9299bd6a4e86dbec10ab7741056f331a18c44a0.tar.gz |
docs: Mark 'client use spnego principal' as deprecated and also a bad idea.
Bug 10888 - smbclient doesn't ignore "not_defined_in_RFC4178@please_ignore"
https://bugzilla.samba.org/show_bug.cgi?id=10888
Signed-off-by: Jeremy Allison <jra@samba.org>
Reviewed-by: Stefan (metze) Metzmacher <metze@samba.org>
Diffstat (limited to 'docs-xml')
-rw-r--r-- | docs-xml/smbdotconf/security/clientusepsnegoprincipal.xml | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/docs-xml/smbdotconf/security/clientusepsnegoprincipal.xml b/docs-xml/smbdotconf/security/clientusepsnegoprincipal.xml index 6ec1eb11165..792a7386f36 100644 --- a/docs-xml/smbdotconf/security/clientusepsnegoprincipal.xml +++ b/docs-xml/smbdotconf/security/clientusepsnegoprincipal.xml @@ -14,6 +14,10 @@ servers known only by IP address. Kerberos relies on names, so ordinarily cannot function in this situation. </para> + <para>This is a VERY BAD IDEA for security reasons, and so this + parameter SHOULD NOT BE USED. It will be removed in a future + version of Samba.</para> + <para>If disabled, Samba will use the name used to look up the server when asking the KDC for a ticket. This avoids situations where a server may impersonate another, soliciting authentication @@ -23,6 +27,9 @@ <para>Note that Windows XP SP2 and later versions already follow this behaviour, and Windows Vista and later servers no longer supply this 'rfc4178 hint' principal on the server side.</para> + + <para>This parameter is deprecated in Samba 4.2.1 and will be removed + (along with the functionality) in a later release of Samba.</para> </description> <value type="default">no</value> </samba:parameter> |