[linux-cifs-client] Re: [PATCH] Add support for using server supplied principal (mic option)

Igor Mammedov niallain at gmail.com
Mon Aug 25 09:03:35 GMT 2008


Love Hörnquist Åstrand wrote:
> 25 aug 2008 kl. 02.25 skrev Jeff Layton:
> 
>> So that I understand correctly, what exactly is the risk of using the
>> server-provided principal?
> 
> I'm not saying that you shouldn't commit the fix if you think i helps  
> interopability, but we should fix all the components so we get a  
> secure solution that works with msft client/server, at least some day.
> 
> Love

So what we will do?
Shall I make it disabled by default and add an option to cifs.upcall to
enable it or we just stick to a secure behavior and forget about servers
with several names in DNS and the only one in ADS?

-- 

Best regards,

-------------------------
Igor Mammedov,
niallain "at" gmail.com






More information about the linux-cifs-client mailing list