From be71039be4edf90f28704026aa3d16da0848231c Mon Sep 17 00:00:00 2001 From: Stefan Metzmacher Date: Tue, 13 Jul 2021 21:26:19 +0200 Subject: docs-xml: add "client/server smb3 signing algorithms" options Signed-off-by: Stefan Metzmacher Reviewed-by: Jeremy Allison --- lib/param/loadparm.c | 7 +++++++ lib/param/loadparm.h | 1 + 2 files changed, 8 insertions(+) (limited to 'lib/param') diff --git a/lib/param/loadparm.c b/lib/param/loadparm.c index 6bfbe1077f6..59e749d9d46 100644 --- a/lib/param/loadparm.c +++ b/lib/param/loadparm.c @@ -2980,6 +2980,13 @@ struct loadparm_context *loadparm_init(TALLOC_CTX *mem_ctx) "winbind use krb5 enterprise principals", "yes"); + lpcfg_do_global_parameter(lp_ctx, + "client smb3 signing algorithms", + DEFAULT_SMB3_SIGNING_ALGORITHMS); + lpcfg_do_global_parameter(lp_ctx, + "server smb3 signing algorithms", + DEFAULT_SMB3_SIGNING_ALGORITHMS); + lpcfg_do_global_parameter(lp_ctx, "client smb3 encryption algorithms", DEFAULT_SMB3_ENCRYPTION_ALGORITHMS); diff --git a/lib/param/loadparm.h b/lib/param/loadparm.h index 0f2af4f4167..cae1a2c7de3 100644 --- a/lib/param/loadparm.h +++ b/lib/param/loadparm.h @@ -285,6 +285,7 @@ enum samba_weak_crypto { #define DEFAULT_SMB2_MAX_TRANSACT (8*1024*1024) #define DEFAULT_SMB2_MAX_CREDITS 8192 +#define DEFAULT_SMB3_SIGNING_ALGORITHMS "aes-128-cmac hmac-sha-256" #define DEFAULT_SMB3_ENCRYPTION_ALGORITHMS "aes-128-gcm aes-128-ccm aes-256-gcm aes-256-ccm" #define LOADPARM_EXTRA_LOCALS \ -- cgit v1.2.1