summaryrefslogtreecommitdiff
path: root/docs/smbdotconf/security/serverschannel.xml
diff options
context:
space:
mode:
Diffstat (limited to 'docs/smbdotconf/security/serverschannel.xml')
-rw-r--r--docs/smbdotconf/security/serverschannel.xml25
1 files changed, 25 insertions, 0 deletions
diff --git a/docs/smbdotconf/security/serverschannel.xml b/docs/smbdotconf/security/serverschannel.xml
new file mode 100644
index 0000000000..8aecc32daa
--- /dev/null
+++ b/docs/smbdotconf/security/serverschannel.xml
@@ -0,0 +1,25 @@
+<samba:parameter name="server schannel"
+ context="G"
+ type="boolean-auto"
+ basic="1"
+ xmlns:samba="http://samba.org/common">
+<description>
+ <para>This controls whether the server offers or even
+ demands the use of the netlogon schannel.
+ <parameter>server schannel = no</parameter> does not
+ offer the schannel, <parameter>server schannel =
+ auto</parameter> offers the schannel but does not
+ enforce it, and <parameter>server schannel =
+ yes</parameter> denies access if the client is not
+ able to speak netlogon schannel. This is only the case
+ for Windows NT4 before SP4.</para>
+
+ <para>Please note that with this set to
+ <parameter>no</parameter> you will have to apply the
+ WindowsXP requireSignOrSeal-Registry patch found in
+ the docs/Registry subdirectory.</para>
+</description>
+
+<value type="default">auto</value>
+<value type="example">yes</value>
+</samba:parameter>