Opportunities for Samba4 based CIFS proxies

Andrew Bartlett abartlet at samba.org
Thu Nov 3 22:34:21 GMT 2005


On Thu, 2005-11-03 at 17:27 -0500, Michael B Allen wrote:
> On Thu, 3 Nov 2005 11:05:09 +0100
> Volker Lendecke <Volker.Lendecke at SerNet.DE> wrote:
> 
> > On Wed, Nov 02, 2005 at 06:41:08PM +0100, Love wrote:
> > > And even better, the store-afs-keyfile-in-ldb hack can go away,
> > > assuming Heimdal and libkafs (or libkrbafs), and be replaced with:
> > 
> > Assuming that all clients send us Kerberos tickets. What can we do if they fall
> > back to ntlm?
> 
> Note, you can proxy NTLM. You just can't delegate.

It is a pain with smb signing, but I expect to be playing some very
interesting games here in the next little while.  (Not that it helps
AFS).

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20051104/4b44a210/attachment.bin


More information about the samba-technical mailing list