[PATCH] SAMR password changes in Samba4

tridge at samba.org tridge at samba.org
Wed Aug 22 02:58:56 GMT 2007


Andrew,

 > This removes one of the validation parts from OemChangePasswordUser2.
 > Can someone else verify that this doesn't provide a route for an
 > attacker?  

as we discussed on IRC, this looks fine to me. The cross-hash checks
seem to be redundent.

I suspect we should check them if supplied though.

Cheers, Tridge


More information about the samba-technical mailing list