svn commit: samba r21991 - in branches/SAMBA_3_0/source: include lib libsmb smbd

Andrew Bartlett abartlet at samba.org
Fri Mar 30 10:35:49 GMT 2007


On Fri, 2007-03-30 at 12:32 +0200, Stefan (metze) Metzmacher wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Volker Lendecke schrieb:
> > On Fri, Mar 30, 2007 at 11:43:11AM +0200, Stefan (metze) Metzmacher wrote:
> >> We could also create a new call at SMB level maybe SMBsesssetup2?
> >>
> >> There're a lot of free message numbers. Are there also some ranges
> >> defined? Or were the number randomly picked by the first implementor of
> >> a call?
> > 
> > Naa, I would not go there. If we have to pass stuff through
> > trans2, that's what it costs.
> 
> Then I'd say it should be a trans2 call on the IPC$ share.
> 
> Is that trans2 call a replacement for the session setup?
> or is it just an 'switch on encryption for the next request'
> on the already created gssapi session?

While that would be entirely sane, no currently it is a full, additional
session setup.  I like the idea of it being 'switch on sealing'...

(The conflict between GSSAPI and the raw krb5 stuff would be a bit of a
pain in Samba3, but not impossible). 

Andrew Bartlett
-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.                  http://redhat.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20070330/f564fc33/attachment.bin


More information about the samba-technical mailing list