Anyone seen SMB2 signing issues with Hitachi HNAS?

Aurélien Aptel aaptel at suse.com
Wed Feb 26 17:50:40 UTC 2020


Richard Sharpe via samba-technical <samba-technical at lists.samba.org>
writes:
> Tried connecting with smbclient and on the Session Setup response,
> which is signed we exit with "Bad SMB2 signature for message".
>
> I tested against a Windows 2012 DC and a capture shows that the DC is
> also signing the SMB2 Session Setup response and smbclient has no
> problems with it.
>
> Is this something broken with the HNAS?

* Signing key generation changed between SMB 3.0 and 3.11, is the HNAS
  using the same dialect your 2012 DC?

* Signing keys are generated based on the Session Key (which comes from
  kerberos or NTLMSSP) and it uses time as input. Maybe check the clocks
  are not too far off from each other.

Cheers,
-- 
Aurélien Aptel / SUSE Labs Samba Team
GPG: 1839 CB5F 9F5B FB9B AA97  8C99 03C8 A49B 521B D5D3
SUSE Software Solutions Germany GmbH, Maxfeldstr. 5, 90409 Nürnberg, DE
GF: Felix Imendörffer, Mary Higgins, Sri Rasiah HRB 247165 (AG München)



More information about the samba-technical mailing list