0001-s3-profile-Use-SHA1-for-hashing-in-profiling-functio.patch
0002-lib-crypto-Fix-path-to-header-file-in-gnutls_helpers.patch
0003-lib-crypto-Add-GNUTLS_FIPS140_SET_-LAX-STRICT-_MODE-.patch
0004-s3-profile-Allow-profile-subsystem-to-use-SHA1-in-FI.patch
0005-lib-util-Use-GnuTLS-random-number-generator-in-genra.patch
0006-lib-crypto-Document-gnutls_error_to_werror.patch
0007-lib-crypto-Document-samba_gnutls_arcfour_confounded_.patch
0008-s3-rpc_client-Return-NTSTATUS-for-init_samr_CryptPas.patch
0009-s3-rpc_client-Return-NTSTATUS-for-init_samr_CryptPas.patch
0010-libcli-auth-Return-NTSTATUS-for-encode_or_decode_arc.patch
0011-libcli-auth-Add-test-for-decoding-an-RC4-password-bu.patch
0012-s3-rpc_client-Use-samba_gnutls_arcfour_confounded_md.patch
0013-s3-rpc_client-Use-GnuTLS-RC4-in-init_samr_CryptPassw.patch
0014-libcli-auth-Use-samba_gnutls_arcfour_confounded_md5-.patch
0015-libcli-auth-Rename-encode_or_decode_arc4_passwd_buff.patch
0016-libcli-auth-Pass-samr_CryptPasswordEx-to-decode_rc4_.patch
0017-libcli-auth-Add-encode_rc4_passwd_buffer.patch
0018-libcli-auth-Add-test-for-encode_rc4_passwd_buffer.patch
0019-s3-rpc_client-Use-encode_rc4_passwd_buffer-in-init_s.patch
0020-s4-libnet-Use-encode_rc4_passwd_buffer-in-libnet_Set.patch
0021-s4-libnet-Use-encode_rc4_passwd_buffer-in-libnet_Set.patch
0022-s4-libnet-Use-GnuTLS-RC4-in-libnet_SetPassword_samr_.patch
0023-s4-libnet-Use-GnuTLS-RC4-in-libnet_SetPassword_samr_.patch
0024-s4-libnet-Use-GnuTLS-RC4-in-libnet_ChangePassword_sa.patch
0025-libcli-auth-Return-WERROR-for-encode_wkssvc_join_pas.patch
0026-libcli-auth-Add-test-for-encode-decode-_wkssvc_join_.patch
0027-libcli-auth-Use-samba_gnutls_arcfour_confounded_md5-.patch
0028-libcli-auth-Use-samba_gnutls_arcfour_confounded_md5-.patch
0029-auth-ntlmssp-Use-GnuTLS-RC4-in-ntlmssp-client.patch
0030-auth-ntlmssp-Use-GnuTLS-RC4-for-ntlmssp-signing.patch
0031-s3-libsmb-Use-GnuTLS-RC4-in-clirap.patch
0032-s3-rpc_client-Use-init_samr_CryptPassword-in-cli_sam.patch
0033-s3-rpc_server-Use-GnuTLS-RC4-in-samr-password-check.patch
0034-s3-rpc_server-Use-GnuTLS-RC4-to-decrypt-samr-passwor.patch
0035-s3-utils-Use-GnuTLS-RC4-in-ntlm_auth.patch
0036-s4-rpc_server-Use-samba_gnutls_arcfour_confounded_md.patch
0037-s4-rpc_server-Use-GnuTLS-RC4-for-samr-password.patch
0038-s4-torture-Use-GnuTLS-RC4-for-RAP-SAM-test.patch
0039-s4-torture-Use-init_samr_CryptPassword-Ex-in-samba3r.patch
0040-s4-torture-Use-init_samr_CryptPassword-in-test_SetUs.patch
0041-s4-torture-Use-init_samr_CryptPassword-in-test_SetUs.patch
0042-s4-torture-Use-init_samr_CryptPassword-in-test_SetUs.patch
0043-s4-torture-Use-init_samr_CryptPassword-in-test_SetUs.patch
0044-s4-torture-Use-init_samr_CryptPassword-in-test_SetUs.patch
0045-s4-torture-Use-GnuTLS-RC4-in-test_OemChangePasswordU.patch
0046-s4-torture-Use-init_samr_CryptPassword-in-test_Chang.patch
0047-s4-torture-Use-init_samr_CryptPassword-in-test_Chang.patch
0048-s4_torture-Use-GnuTLS-RC4-in-test_ChangePasswordUser.patch
0049-s4-torture-Use-GnuTLS-RC4-in-test_ChangePasswordUser.patch
0050-s4-torture-Use-init_samr_CryptPassword-in-test_Chang.patch
0051-s4-torture-clarify-comments-and-variable-names-in-Ch.patch
0052-s4-torture-Use-init_samr_CryptPassword-in-test_Chang.patch
0053-s4-torture-Use-GnuTLS-RC4-in-test_ChangePasswordRand.patch
0054-s4-torture-Use-samba_gnutls_arcfour_confounded_md5-i.patch
0055-s4-torture-Use-init_samr_CryptPassword-in-testjoin-R.patch
0056-lib-crypto-Use-GnuTLS-RC4-in-py_crypto.patch
0057-lib-crypto-Remove-arcfour.h-from-crypto.h.patch
0058-lib-crypto-Don-t-build-RC4-if-we-have-GnuTLS-3.4.7.patch
0059-s3-lib-Use-the-passed-mem_ctx-instead-of-talloc_tos.patch
0060-s3-rpcclient-Use-a-stackframe-for-temporary-memory.patch
0061-s3-utils-Use-a-stackframe-for-temporary-memory.patch
0062-s3-rpc_server-Use-a-stackframe-for-temporary-memory.patch
0063-netlogon-Fix-potential-use-of-uninitialized-variable.patch
0064-s3-rpc_server-Only-dump-passwords-in-developer-build.patch
0065-libcli-smb-Add-forward-declaration-for-gnutls_hmac_h.patch
0066-s3-modules-Link-vfs_acl_common-against-gnutls.patch
0067-lib-util-Add-generate_nonce_buffer.patch
0068-libcli-smb-Use-generate_nonce_buffer-for-AES-CCM-and.patch
0069-s3-smbd-Use-generate_nonce_buffer-for-AES-CCM-and-AE.patch
0070-lib-util-Add-better-documentation-for-generate_secre.patch
0071-s4-rpc_server-Use-generate_secret_buffer-to-create-a.patch
0072-s4-rpc_server-Use-generate_secret_buffer-for-backupk.patch
0073-s4-rpc_server-Use-generate_secret_buffer-for-netlogo.patch
0074-libcli-auth-Use-generate_secret_buffer-for-netlogon-.patch
0075-lib-util-Fix-documentation-for-random-number-functio.patch
0076-Revert-libcli-auth-Use-generate_secret_buffer-for-ne.patch
0077-Revert-s4-rpc_server-Use-generate_secret_buffer-for-.patch
0078-Revert-s4-rpc_server-Use-generate_secret_buffer-for-.patch
0079-Revert-s4-rpc_server-Use-generate_secret_buffer-to-c.patch
0080-lib-util-Use-generate_secret_buffer-for-long-term-pa.patch
0081-s4-samdb-Use-generate_nonce_buffer-for-AEC-GCM-nonce.patch
0082-s3-passdb-Use-generate_secret_buffer-for-generating-.patch
0083-auth-ntlmssp-Use-generate_random_buffer-for-session-.patch
0084-encrypted_secrets-Add-known-and-expected-value-test.patch
0085-s4-samdb-Remove-dual-stack-mode-from-test_-encrypted.patch
0086-s4-samdb-Only-include-necessary-header-files-in-encr.patch
0087-waf-Check-for-GNUTLS-AES-CFB-support.patch
0088-libcli-auth-Use-netlogon_creds_aes_encrypt-in-netlog.patch
0089-libcli-auth-Use-GnuTLS-AES128-CFB-for-netlogon_creds.patch
0090-libcli-auth-Return-NTSTATUS-for-netlogon_creds_aes_e.patch
0091-libcli-auth-Use-GnuTLS-AES128-CFB-for-netlogon_creds.patch
0092-libcli-auth-Return-NTSTATUS-from-netlogon_creds_aes_.patch
0093-crypto-Update-REQUIREMENTS-file-with-new-minimum-ver.patch
0094-libcli-auth-Check-NTSTATUS-from-netlogon_creds_aes_-.patch
0095-s3-rpc_server-Check-NTSTATUS-return-value-from-netlo.patch
0096-s4-rpc_server-Check-NTSTATUS-return-value-from-netlo.patch
0097-s3-librpc-Remove-unused-init_netr_CryptPassword.patch
0098-auth-credentials-Check-NTSTATUS-return-from-netlogon.patch
0099-auth-gensec-Use-GnuTLS-AES128-CFB8-in-netsec_do_seq_.patch
0100-auth-gensec-Use-gnutls_error_to_ntstatus-consistentl.patch
0101-auth-gensec-Use-GnuTLS-AES-CFB8-in-netsec_do_seal.patch
0102-auth-gensec-Use-gnutls_error_to_ntstatus-in-netsec_d.patch
0103-lib-crypto-Prepare-not-to-build-AES-or-AES-CMAC-if-w.patch
0104-build-Set-minimum-GnuTLS-version-at-3.4.7.patch
0105-s4-rpc_server-Remove-Heimdal-based-BackupKey-server.patch
0106-s4-rpc_server-backupkey-consistently-check-error-cod.patch
0107-lib-crypto-Remove-unused-RC4-code-from-Samba.patch
0108-s4-samdb-Remove-duplicate-encrypted_secrets-code-usi.patch
0109-build-Remove-explicit-check-for-HAVE_GNUTLS_AEAD-as-.patch
0110-libcli-smb-Define-SMB2_AES_128_CCM_NONCE_SIZE.patch
0111-libcli-smb-Use-GnuTLS-for-AES-constants.patch
0112-libcli-smb-Add-gnutls_aead_cipher_hd_t-to-smb2_signi.patch
0113-libcli-smb-Use-a-smb2_signing_key-for-storing-the-en.patch
0114-libcli-smb-Use-a-smb2_signing_key-for-storing-the-de.patch
0115-s3-smbd-Use-smb2_signing_key-structure-for-the-encry.patch
0116-s3-smbd-Use-smb2_signing_key-structure-for-the-decry.patch
0117-s3-smbd-Use-GnuTLS-for-AES-constants.patch
0118-waf-Check-for-AES128-CMAC-support-in-GnuTLS.patch
0119-libcli-smb-Use-GnuTLS-AES128-CMAC-in-smb2_signing_si.patch
0120-libcli-smb-Use-gnutls_error_to_ntstatus-in-smb2_sign.patch
0121-libcli-smb-Use-GnuTLS-AES128-CMAC-in-smb2_signing_ch.patch
0122-libcli-smb-Use-gnutls_error_to_ntstatus-in-smb2_sign.patch
0123-lib-crypto-Do-not-build-AES-CMAC-if-we-use-GnuTLS-th.patch
0124-libcli-smb-Support-GnuTLS-AES-CCM-and-GCM-in-smb2_si.patch
0125-libcli-smb-Support-GnuTLS-AES-CCM-and-GCM-in-smb2_si.patch
0126-libcli-smb-Use-smb2_signing_key-in-smb2_signing_decr.patch
0127-libcli-smb-Use-gnutls_error_to_ntstatus-in-smb2_sign.patch
0128-libcli-smb-Use-smb2_signing_key-in-smb2_signing_encr.patch
0129-libcli-smb-Use-gnutls_error_to_ntstatus-in-smb2_sign.patch
0130-libcli-smb-Prefer-AES-GCM-over-AES-CCM-with-GnuTLS.patch
0131-s3-smbd-Prefer-AES-GCM-over-AES-CCM-with-GnuTLS.patch
0132-auth-gensec-fix-non-AES-schannel-seal.patch
0133-auth-gensec-fix-AES-schannel-seal-and-unseal.patch
0134-libcli-auth-add-gnutls-test-for-aes-128-cfb8-cipher-.patch
0135-waf-Check-for-gnutls_aead_cipher_encryptv2.patch
0136-libcli-smb-Use-gnutls_aead_cipher_encryptv2-for-AES-.patch
0137-libcli-smb-Use-gnutls_aead_cipher_decryptv2-for-AES-.patch
0138-libcli-smb-Do-not-use-gnutls_aead_cipher_encryptv2-w.patch
0139-libcli-auth-Return-NTSTATUS-for-SMBOWFencrypt_ntv2.patch
0140-libcli-auth-Check-return-codes-of-SMBsesskeygen_ntv2.patch
0141-libcli-auth-Return-NTSTATUS-for-SMBOWFencrypt_ntv2.patch
0142-libcli-auth-Check-return-code-of-SMBOWFencrypt_ntv2.patch
0143-s4-rpc_server-Remove-gnutls_global_-de-init.patch
0144-s4-lib-Remove-gnutls_global_-de-init-from-libtls.patch
0145-s4-torture-Remove-calls-to-gnutls_global_-de-init-in.patch
0146-libcli-auth-Check-return-value-of-netlogon_creds_ini.patch
0147-libcli-auth-Check-return-status-of-netlogon_creds_in.patch
0148-libcli-auth-Check-return-status-of-netlogon_creds_fi.patch
0149-libcli-auth-Return-NTSTATUS-for-netlogon_creds_clien.patch
0150-auth-pycreds-Check-return-code-of-netlogon_creds_cli.patch
0151-libcli-auth-Check-return-code-of-netlogon_creds_clie.patch
0152-s4-librpc-Check-return-code-of-netlogon_creds_client.patch
0153-libcli-auth-Check-return-code-of-netlogon_creds_step.patch
0154-libcli-auth-Check-return-code-of-netlogon_creds_step.patch
0155-libcli-auth-Check-return-code-of-netlogon_creds_aes_.patch
0156-s3-rpc_server-Replace-E_md5hash-with-GnuTLS-calls.patch
0157-s3-winbindd-Replace-E_md5hash-with-GnuTLS-calls.patch
0158-s3-winbind-Replace-E_md5hash-with-GnuTLS-calls.patch
0159-libcli-auth-Remove-unused-E_md5hash.patch
0160-s4-lib-tls-Fix-cert-and-privkey-types.patch
0161-winbind-Fix-CID-1455915-Resource-leak.patch
0162-auth-tests-Improve-debug-output-of-test_gnutls.patch
0163-auth-tests-Only-enable-torture_gnutls_aes_128_cfb-on.patch
0164-libcli-auth-test-des_crypt56-and-add-test_gnutls-to-.patch
0165-selftest-test-E_P16.patch
0166-selftest-test-sam_rid_crypt.patch
0167-selftest-test-E_P24-and-SMBOWFencrypt.patch
0168-selftest-test-E_old_pw_hash.patch
0169-selftest-test-des_crypt128.patch
0170-selftest-test-des_crypt112-and-fix-unused-decryption.patch
0171-selftest-test-des_crypt112_16.patch
0172-selftest-test-SMBsesskeygen_lm_sess_key.patch
0173-selftest-test-sess_crypt_blob.patch
0174-smbdes-add-des_crypt56_gnutls-using-DES-CBC-with-zer.patch
0175-netlogon_creds_des_encrypt-decrypt_LMKey-use-gnutls-.patch
0176-SMBsesskeygen_lm_sess_key-use-gnutls-and-return-NTST.patch
0177-smbdes-convert-sam_rid_crypt-to-use-gnutls.patch
0178-smbdes-convert-E_P16-to-use-gnutls.patch
0179-smbdes-remove-D_P16-not-used.patch
0180-smbdes-convert-E_P24-and-SMBOWFencrypt-to-use-gnutls.patch
0181-smbdes-convert-des_crypt128-to-use-gnutls.patch
0182-smbdes-convert-E_old_pw_hash-to-use-gnutls.patch
0183-smbdes-convert-des_crypt112-to-use-gnutls.patch
0184-smbdes-convert-des_crypt112_16-to-use-gnutls.patch
0185-session-convert-sess_crypt_blob-to-use-gnutls.patch
0186-sess_crypt_blob-can-only-crypt-blobs-whose-size-divi.patch
0187-smbdes-remove-old-unused-DES-builtin-crypto.patch
0188-lib-crypto-Remove-our-implementation-of-AES-CCM.patch
0189-lib-crypto-Remove-our-implementation-of-AES-GCM.patch
0190-lib-crypto-Only-build-AES-code-if-we-need-AES-CMAC.patch
0191-lib-crypto-Build-intel-aes-ni-only-if-GnuTLS-doesn-t.patch
0192-lib-crypto-Add-samba_gnutls_weak_crypto.patch
0193-s3-utils-Add-weak-crypto-information-to-testparm.patch
0194-lib-param-Add-lp-cfg-_weak_crypto.patch
0195-gensec-Add-a-check-if-a-gensec-module-implements-wea.patch
0196-auth-ntlmssp-Mark-as-weak_crypto.patch
0197-s3-param-Force-SMB-encryption-for-DECRPC-over-named-.patch
0198-s3-param-Only-allow-SMB-3.0-for-DCERPC-client-connec.patch
0199-s3-rpc_server-Allow-RC4-encrypted-buffers-in-samr_Se.patch
0200-s4-rpc_server-Allow-to-use-RC4-for-setting-passwords.patch
0201-s3-rpc_server-Only-announce-RC4-in-netlogon-server-i.patch
0202-s4-rpc_server-Only-announce-RC4-in-netlogon-server-i.patch
0203-s4-samdb-Allow-to-hash-password-using-MD5-in-samdb.patch
0204-lib-crypto-Allow-py_crypto-to-use-RC4-in-FIPS-mode.patch
0205-param-Do-not-use-weak-crypto-for-kerberos-if-disallo.patch
0206-param-Do-not-use-weak-crypto-in-ldap-server-if-disal.patch
0207-libcli-auth-If-weak-crypto-is-disallowed-reject-md5-.patch
0208-s3-librpc-Only-use-RC4-if-our-systems-supports-it.patch
0209-s3-rpcserver-fix-security-level-check-for-DsRGetFore.patch
0210-support-krb5-1.18.patch
CVE-2019-14907-4.11.patch
README.downgrade
krb5_no_des_411.patch
pam_winbind.conf
samba-4.10-fix-netbios-join.patch
samba-4.11.2.tar.asc
samba-4.11.3-fix_smb1_cli_qpathinfo_2_3.patch
samba-4.11.3-only_link_libnsl_libsocket_if_needed.patch
samba-4.11.7-fix_segfault_in_smbd_do_qfilepathinfo.patch
samba-4.11.7-fix_smbclient_debug_spam.patch
samba.logrotate
samba.pamd
smb.conf.example
smb.conf.vendor
README.downgrade
Downgrading Samba ================= Short version: data-preserving downgrades between Samba versions are not supported Long version: With Samba development there are cases when on-disk database format evolves. In general, Samba Team attempts to maintain forward compatibility and automatically upgrade databases during runtime when requires. However, when downgrade is required Samba will not perform downgrade to existing databases. It may be impossible if new features that caused database upgrade are in use. Thus, one needs to consider a downgrade procedure before actually downgrading Samba setup. Please always perform back up prior both upgrading and downgrading across major version changes. Restoring database files is easiest and simplest way to get to previously working setup. Easiest way to downgrade is to remove all created databases and start from scratch. This means losing all authentication and domain relationship data, as well as user databases (in case of tdb storage), printers, registry settings, and winbindd caches. Remove databases in following locations: /var/lib/samba/*.tdb /var/lib/samba/private/*.tdb In particular, registry settings are known to prevent running downgraded versions (Samba 4 to Samba 3) as registry format has changed between Samba 3 and Samba 4.