The `tls cafile` setting in `smb.conf` is not necessary. It is used for verifying peer certificates for mutual TLS authentication, not to specify the intermediate certificate authority chain like I thought. The setting cannot simply be left out, though. If it is not specified, Samba will attempt to load a file from a built-in default path, which will fail, causing the server to crash. This is avoided by setting the value to the empty string. |
||
---|---|---|
.. | ||
krb5.conf.j2 | ||
smb.conf.j2 | ||
sysvolsync.ssh_known_hosts.j2 |