Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-8772: Centrify Recommendations for Samba security alert - CVE-2017-7494 (SambaCry)

Centrify DirectControl ,  

25 May,17 at 10:53 PM

Applies to: All supported versions of Centrify Adbindproxy on all supported platforms. 

Question:
What are Centrify's recommendations in regards to Samba security alert - CVE-2017-7494​?

Answer:
With regards to CVE-2017-7494, Centrify is no longer shipping Samba, only the adbindproxy package to interoperate Centrify with Samba. Please follow Samba's recommendations for this security alert.

Note: 
- Centrify-Samba and stock Samba version 3.x, is no longer supported because version 3.x is end-of-life by samba.org.
- If a patch/upgrade is applied to Samba be sure to re-run adbindproxy.pl script and restart samba using our startup script. For example on RHEL 7.x systems:

systemctl restart centrifydc-samba.


Here are the latest release notes for adbindproxy. Specifically, it highlights our recommendation with regards to Samba:

Centrify ADBindProxy is a proxy agent package that seamlessly integrates the DirectControl agent in Centrify Server Suite with open source Samba (referred to as stock Samba in this document), enabling the two products to share Active Directory user and group membership and to agree upon Unix identity attributes for Active Directory users. It is a proxy that passes identity management requests from Samba to DirectControl.

This Centrify ADBindProxy release supports stock Samba version 4.x. You are strongly advised to apply the latest security patches from Samba first before deploying Centrify ADBindProxy.


Please also review:
KB-6842: Overview of the steps to upgrade or migrate from Centrify-enabled Samba to stock Samba with Centrify Adbindproxy
KB-6731: Impact of Badlock (CVE-2016-0128/CVE-2016-2118) on Centrify-Enabled Samba
Centrify Adbindproxy 5.4.0 Release Notes



Centrify Corporation does not take any responsibility for the content or availability of this link and it was provided as a courtesy. Customers should contact the vendor if there are any further questions

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.