Patch for 4365?

Gerald (Jerry) Carter jerry at samba.org
Thu Mar 1 21:34:01 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Andrew Bartlett wrote:

>> (7:55:12 AM) coffeedude: vl: WT...?  That's strange....ok
>> 	So they should be the same but if was the case
>> 	sensitive domain name string sent by the client
>> 	that was used to generate the NTLMv2 response.
>> 	Kind of makes sense then
>> (7:55:22 AM) coffeedude: I'll upload the patch and get
>> 	the reporter to test
> 
> This all seems very reasonable given the way the HMAC in NTLMv2
> operates.

just got confirmation on the bug.  The original reporter
agrees.

Volker,  I'll leave this to you to checkin and close out.




cheers, jerry
=====================================================================
Samba                                    ------- http://www.samba.org
Centeris                         -----------  http://www.centeris.com
"What man is a man who does not make the world better?"      --Balian
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF50bIIR7qMdg1EfYRAgH5AJ4iO4lMjRcwqixHL03Iv8Qk8KvhBwCg0RT4
RbMPKDFoLvuMIQ0MBF3Xgos=
=YeI6
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list