Default encrypted passwords = yes?

Gerald (Jerry) Carter jerry at samba.org
Thu Sep 27 12:10:02 GMT 2001


On Thu, 27 Sep 2001, James Nord wrote:

> I always *assumed* (oops ;-) ) that if I had that to yes smbclient
> would never use clear-text passwords.

When connecting to the Samba server using that smb.conf
you are correct.  :-)

This is the same thing MS did with Windows NT 4.0 SP3.
Because smbclient is one of the main tools used for testing
a samba installation, I don't think it should default to
reject connecting to clear text servers.  This behavior could
be specified as a command line option, but not as a default
(unless "encrypt passwords = yes" was the default for smbd).

To change this would be to shoot ourselves in the foot.


> Is there no way for smbclient to refuse to use clear text? If so I
> would consider this a feature/security bug.

See above.






cheers, jerry
 ---------------------------------------------------------------------
 www.samba.org              SAMBA Team              jerry_at_samba.org
 www.plainjoe.org                                jerry_at_plainjoe.org
 --"I never saved anything for the swim back." Ethan Hawk in Gattaca--





More information about the samba-technical mailing list