Never send the LM response on cached credentials

Jeremy Allison jra at samba.org
Tue Aug 29 05:23:43 GMT 2006


On Tue, Aug 29, 2006 at 12:49:02PM +1000, Andrew Bartlett wrote:
> 
> What I would like to do is have a higher standard for the cached
> credentials (as they are being sent without prompting).  

I'm not sure what you mean by being sent "without prompting" ?

> However, for this new code and functionality, and given that we are
> adding a new feature that operates automatically, without user
> interaction, I would like a higher, more secure standard.

We're obeying the settings in the smb.conf for NTLM
auth. What more do you expect ?

I guess I'm unsure what the problem you're having with this
is. Can you explain a little more clearly what you'd like
this to do ?

Jeremy.


More information about the samba-technical mailing list