[cifs-protocol] RE: KVNO of trusts

John Dunning johndun at microsoft.com
Wed Nov 5 21:43:28 GMT 2008

Hello Andrew,
   It sounds like you are very busy with other issues at the moment. Would be it be okay with you to put this particular question on hold until you have a chance to revisit the repro? If so you can just let me know when you are ready to proceed.

John Dunning
Senior Escalation Engineer Microsoft Corporation
Email: johndun at microsoft.com
Tele: (469)775-7008

-----Original Message-----
From: Andrew Bartlett [mailto:abartlet at samba.org]
Sent: Monday, November 03, 2008 5:44 PM
To: John Dunning
Cc: Interoperability Documentation Help; pfif at tridgell.net; cifs-protocol at samba.org
Subject: RE: KVNO of trusts

On Mon, 2008-11-03 at 12:26 -0800, John Dunning wrote:
> Hello Andrew,
>    I have been looking through some of the network traces that Richard Guthrie obtained during the plugfest. Although I did find one that had the call to CreateTrustedDomainEx the fields that I am interested in, in particular the Authblob, are encrypted.
> Would it be possible for you to supply an NDR dump of the behavior that you are describing?

These are the decrypted blobs.  They don't show the version number being exchanged.  The KDC interaction I saw at the plugfest - I don't have a trace for at this time (just not had a chance to reproduce it).

Andrew Bartlett

Andrew Bartlett
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.

More information about the cifs-protocol mailing list