Comment 28 for bug 2027716

Revision history for this message
RedScourge (redscourge) wrote :

On this note, while it's a bit disturbing that the entire Samba dev community seems to have been totally blindsided by this catastrophic issue which has apparently been over 8 months in the making, does anyone happen to know if the devs are aware of the big pending October 2023 change whereby Kerberos RC4-HMAC becomes enforced, and whether that is likely to break Samba in this same way too? See https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37966 and https://support.microsoft.com/en-us/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d