TNG works with Win2k, fails with Win98

Luke Kenneth Casson Leighton lkcl at samba.org
Mon Feb 21 05:53:37 GMT 2000


:)actually, nobody else anticipated anybody like me, including myself.  if
you do a cvs update this line will disappear.

*however*... it seems like you've brought up a _really_ important point:
there is a race condition that can result in intermittent login failures.

hmmm....

hmmm.....

how am i going to fix this?

i store the old value, but that's kind-of tacky, reading new value of
$MACHINE.ACC and old value of $MACHINE.ACC and checking _two_ logins!
it wouldn't surprise me if htat's what the NT team chose to do, however,
otherwise they wouldn't have put old value in the LSA-secrets store.

*sigh*.

ok.

so you made a connection, and it failed.  second time, it worked.

thanks for finding this, it would have been one of those bitch-to-find
bugs as it would only come up once a week.

On 20 Feb 2000, Patrick J. LoPresti wrote:

> Luke Kenneth Casson Leighton <lkcl at samba.org> writes:
> 
> > check param/loadparm.c it should have machine_trust_password_timeout =
> > 60*60*24*7, if there's a line saying =60, you got a cvs update _just_ when
> > i was doing some tests :)
> 
> Sure enough, here are two consecutive lines from that file:
> 
>   Globals.machine_password_timeout = 60*60*24*7; /* 7 days default. */
>   Globals.machine_password_timeout = 60; /* 7 days default. */
> 
> 
> OK, that's pretty funny.
> 
> Luke, the designers of CVS never anticipated *anybody* like you.
> 
>  - Pat
> 

<a href=" mailto:lkcl at samba.org" > Luke Kenneth Casson Leighton    </a>
<a href=" http://cb1.com/~lkcl"  > Samba and Network Development   </a>
<a href=" http://samba.org"      > Samba Web site                  </a>
<a href=" http://www.iss.net"    > Internet Security Systems, Inc. </a>
<a href=" http://mcp.com"        > Macmillan Technical Publishing  </a>
 
ISBN1578701503 DCE/RPC over SMB: Samba and Windows NT Domain Internals



More information about the samba-ntdom mailing list