From e07c9c67685230f27c153e35042b0159e7fd8477 Mon Sep 17 00:00:00 2001 From: Karolin Seeger Date: Tue, 30 Oct 2007 07:42:25 +0000 Subject: Add manpage section for the new parameter client ldap sasl wrapping Karolin (This used to be commit 051bb7d548c67a467296abf8895fc156e9ecb4a2) --- docs/smbdotconf/ldap/clientldapsaslwrapping.xml | 43 +++++++++++++++++++++++++ docs/smbdotconf/security/clientsigning.xml | 3 +- 2 files changed, 45 insertions(+), 1 deletion(-) create mode 100644 docs/smbdotconf/ldap/clientldapsaslwrapping.xml diff --git a/docs/smbdotconf/ldap/clientldapsaslwrapping.xml b/docs/smbdotconf/ldap/clientldapsaslwrapping.xml new file mode 100644 index 0000000000..0f85646866 --- /dev/null +++ b/docs/smbdotconf/ldap/clientldapsaslwrapping.xml @@ -0,0 +1,43 @@ + + + + The defines whether + ldap traffic will be signed or signed and encrypted (sealed). + Possible values are plain, sign + and seal. + + + + The values sign and seal + are only available if Samba has been compiled against a modern + OpenLDAP version (2.3.x or higher). + + + + This option is needed in the case of Domain Controllers enforcing + the usage of signed LDAP connections (e.g. Windows 2000 SP3 or higher). + LDAP sign and seal can be controlled with the registry key + "HKLM\System\CurrentControlSet\Services\NTDS\Parameters\LDAPServerIntegrity" + on the Windows server side. + + + + Depending on the used KRB5 library (MIT and older Heimdal versions) + it is possible that the message "integrity only" is not supported. + In this case, sign is just an alias for + seal. + + + + The default value is plain which is not irritable + to KRB5 clock skew errors. That implies synchronizing the time + with the KDC in the case of using sign or + seal. + + +plain + diff --git a/docs/smbdotconf/security/clientsigning.xml b/docs/smbdotconf/security/clientsigning.xml index 02a7ce38a9..bf37cbb874 100644 --- a/docs/smbdotconf/security/clientsigning.xml +++ b/docs/smbdotconf/security/clientsigning.xml @@ -12,7 +12,8 @@ When set to auto, SMB signing is offered, but not enforced. When set to mandatory, SMB signing is required and if set - to disabled, SMB signing is not offered either. + to disabled, SMB signing is not offered either. + auto -- cgit