Fix smartcard offline logon and NTLM authentication

Stefan Metzmacher metze at samba.org
Mon Jun 20 20:55:42 UTC 2016


Hi,

here're some patches to fix smartcard offline logons
and related bugs.

The key part is adding PAC_CREDENTIAL with the NTHASH.

In order to avoid an NTHASH based on a password,
I also implemented the UF_SMARTCARD_REQUIRED feature,
that generates a random NTHASH value, that is only
known to the KDC and the private key of the smartcard.

I may need to add some more BUG: markers, but you can start
with the review now:-)

See
https://git.samba.org/?p=metze/samba/wip.git;a=shortlog;h=refs/heads/master4-smart-ok
it's based on
https://git.samba.org/?p=metze/samba/wip.git;a=shortlog;h=refs/heads/master4-smart-base

Thanks!
metze

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: OpenPGP digital signature
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20160620/9f81b880/signature.sig>


More information about the samba-technical mailing list