Kerberos 5 and NTLMv2 without SPNEGO?

Luke Howard lukeh at padl.com
Wed Jul 2 00:58:49 GMT 2008


On 02/07/2008, at 1:49 AM, Gerald (Jerry) Carter wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Michael B Allen wrote:
>> Dear Cousin,
>>
>> Does anyone know if it's ok to do Kerberos 5 and / or NTLMSSP without
>> SPNEGO for SMB_COM_SESSION_SETUP_ANDX?
>>
>> I'm 95% sure the answer is "yes" but it would be nice if someone gave
>> me assuring pat on the head.
>
> Pretty sure.  Been a while since I looked but I think this is how
> Steve previously did NTLMSSP in the cifs fs.


I think Windows still does raw NTLMSSP too... never seen raw Kerberos  
though, but SSPI is sufficiently well layered that I would expect it  
to work.

-- Luke


More information about the samba-technical mailing list