Two stage login

Gerald Carter gcarter at valinux.com
Thu Feb 15 06:51:17 GMT 2001


Andrew Tridgell wrote:
> 
> It doesn't gain us anything though. The MS clients don't do 
> this, so for Samba as a server it is useless and when Samba 
> is the client its useless because if the client knows the 
> plain text password then the encryption try won't fail (as 
> its a simple mapping from plain text to encrypted).

I think the original intent from the poster was to be able 
to try to logon against the smbpasswd file, and if that 
failes to try the plain text against /etc/passwd (which 
can have a different password).







Cheers, jerry
----------------------------------------------------------------------
   /\  Gerald (Jerry) Carter                     Professional Services
 \/    http://www.valinux.com/  VA Linux Systems   gcarter at valinux.com
       http://www.samba.org/       SAMBA Team          jerry at samba.org
       http://www.plainjoe.org/                     jerry at plainjoe.org

       "...a hundred billion castaways looking for a home."
                                - Sting "Message in a Bottle" ( 1979 )






More information about the samba-technical mailing list