CVS update: samba/source/rpc_server

Andrew Bartlett abartlet at pcug.org.au
Wed Sep 26 09:47:07 EST 2001


Jeremy Allison wrote:
> 
> Date:   Tue Sep 25 14:13:55 2001
> Author: jra
> 
> Update of /data/cvs/samba/source/rpc_server
> In directory va:/tmp/cvs-serv21666/rpc_server
> 
> Modified Files:
>       Tag: SAMBA_2_2
>         srv_netlog_nt.c
> Log Message:
> Moved account disabled check to stop accoutn guessing. Patch from Andrew
> Bartlett.
> Jeremy

For the record:  This means that we are now trusting our security to the
(normally MS windows) domain member.  This is normally fine, but if it
was (for example) HEAD from mid-last-week it would give the game away
itself.  MS domain members munge NT_STATUS_WRONG_PASSWORD and
NT_STATUS_NO_SUCH_USER into NT_STATUS_LOGON_FAILURE, so its normally not
a problem.  Unfortuently we don't have a choice either....

Andrew Bartlett

-- 
Andrew Bartlett                                 abartlet at pcug.org.au
Samba Team member, Build Farm maintainer        abartlet at samba.org
Student Network Administrator, Hawker College   abartlet at hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net




More information about the samba-cvs mailing list