Using SPNEGO/SSPI in SMB

Andrew Bartlett abartlet at samba.org
Fri Aug 19 10:23:41 GMT 2005


On Fri, 2005-08-19 at 02:28 -0700,
samba-technical.10.overbored at spamgourmet.com wrote:
> Wow, thanks for the fast reply.
> 
> Thus spake Andrew Bartlett - abartlet at samba.org on 8/19/2005 1:49 AM:
> > Try 'Negotiate' or 'GSS-SPNEGO' as the mech.  
> 
> Did you mean I should change that string in sspi_auth.cpp (currently 
> "Kerberos")? I changed that to "Negotiate", and it generated the same 
> buffers as "NTLM". (When I tried GSS-SPNEGO, it just fails, saying 
> requested security package not found.)

This is getting of topic for Samba (I really don't know the internals of
SSPI, I've never programmed it).  However, I suspect the choice of
NTLMSSP or SPNEGO depends on details such as the target host
specification.  

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Samba Developer, SuSE Labs, Novell Inc.        http://suse.de
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20050819/d81bc0c1/attachment.bin


More information about the samba-technical mailing list