OL6-00-000272 - The system must use SMB client signing for connecting to samba servers using smbclient.

Information

Packet signing can prevent man-in-the-middle attacks which modify SMB packets in transit.

Solution

To require samba clients running 'smbclient' to use packet signing, add the following to the '[global]' section of the Samba configuration file in '/etc/samba/smb.conf':

client signing = mandatory

Requiring samba clients such as 'smbclient' to use packet signing ensures they can only communicate with servers that support packet signing.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_6_V2R7_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, CCI|CCI-000366, Rule-ID|SV-209010r793731_rule, STIG-ID|OL6-00-000272, STIG-Legacy|SV-65057, STIG-Legacy|V-50851, Vuln-ID|V-209010

Plugin: Unix

Control ID: 2009f4b533ebe25e5ac7e8a49e3e480e4f7619bf0202c8815f8cb9f9f5bc6e42