[Samba] SASL DIGEST-MD5 NT_STATUS_INVALID_PARAMETER

Arthur Ramsey arthur_ramsey at mediture.com
Fri Jul 10 23:59:36 UTC 2015


I was able to get Vaso Identikey server working with Samba4 as the 
backend when deployed on Windows as it uses GSSAPI instead of DIGEST-MD5.
>
> Thanks,
> Arthur
>
> On 07/10/2015 03:29 PM, Andrew Bartlett wrote:
>> On Fri, 2015-07-10 at 11:45 -0500, Arthur Ramsey wrote:
>>> That's too bad, I was trying to get the Vasco Identikey server working
>>> with samba4 as a backend for FIPS 140-2 compliant OTP, which will only
>>> bind with DIGEST-MD5.  I guess I will have to join a Windows 2008 R2 to
>>> the domain as a domain controller.
>> Very interesting.  This is the first use of DIGEST-MD5 that I've come
>> across for AD.
>>
>> It would be great if it could be patched back in, but it would need
>> tests this time, and to actually work.  We may have to implement the
>> server-side in Samba, if we can't push the pre-digested hash values into
>> Cyrus SASL (or don't want to use it).
>>
>> Andrew Bartlett
>>
>





More information about the samba mailing list