NTLMv2

Gerald (Jerry) Carter jerry at samba.org
Mon Nov 26 17:09:35 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Zachary Loafman wrote:
>> -----Original Message-----
>> From: Gerald (Jerry) Carter [mailto:jerry at samba.org]
>> Sent: Monday, November 26, 2007 6:07 AM
>> To: Andrew Bartlett
>> Cc: Zachary Loafman; Volker.Lendecke at SerNet.DE; samba-
>> technical at lists.samba.org
>> Subject: Re: NTLMv2
>>
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> Andrew Bartlett wrote:
>>
>>> I would be very happy to see Samba 3.2 move to NTLMv2
>>> only, but we should clearly document how to disable it
>>> when not supported.  Certainly vendors with much
>>> tighter support arrangements with their customers
>>> could do so with greater certainty than perhaps we
>>> could for upstream Samba.
>> Andrew,
>>
>> IIRC Samba domain controllers would be fine with this.  What
>> Windows servers/DCs would this break?
> 
> NTLMv2 auth is supported on NT4 SP4 and 2k onward. If a Samba 
> DC works fine with it, then it's a pretty safe default.

Does NT4 actually work?  Before I can feel comfortable about it,
we need to confirm that we work with Windows 2000 and later.






jerry
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHSv3PIR7qMdg1EfYRAhInAKC+nIUGtgPM+TfoeWK+Nq9MOtNgIgCg7Znf
Xr+b0/+0IyE5foOUYpq+2r8=
=WVX1
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list