svn commit: samba r21991 - in branches/SAMBA_3_0/source: include lib libsmb smbd

Andrew Bartlett abartlet at samba.org
Fri Mar 30 10:48:48 GMT 2007


On Fri, 2007-03-30 at 12:40 +0200, Stefan (metze) Metzmacher wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Andrew Bartlett schrieb:
> >> does smb signing still work when the first vuid is closed?
> > 
> > The key is persistent.
> 
> what is when the first session setup is anonymous?

The first non-guest login.  The trouble for security from SMB signing is
that the attacker could know this password (perhaps it's their own
password, perhaps it is a 'well known' password).

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Samba Developer, Red Hat Inc.                  http://redhat.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20070330/afdbffe3/attachment.bin


More information about the samba-technical mailing list