Re: Brown-Paper-Bag bugs in the winbind ntlm auth_helper

From: Henrik Nordström <hno@dont-contact.us>
Date: Sat, 21 Sep 2002 08:24:31 +0200 (CEST)

On Fri, 20 Sep 2002 kinkie-ml@libero.it wrote:

> > And I agree with Andrew on the response size issue, but until we have
> > a decent possibility to support NTLMv2 it won't matter very much..
>
> Well, the winbind helper may even figure out what's going on and cope.
> We'll never know until we try.

Only if MS has totally flawed their own implementation of NTLMSSP. For
NTLMv2 to work the challenge packet SHOULD indicate that NTLMv2 is
acceptable, and the client SHOULD have requested NTLMv2 + target info.

If we "fix" Squid to send the full NEGOTIATE packet to the helper and not
reuse challenges implementing NTLMv2 using winbind should be a pretty
trivial task, provided the winbind interface supports NTLMv2 responses.

Regards
Henrik
Received on Sat Sep 21 2002 - 00:24:35 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:16:34 MST