Re: NTLM

From: Andrew Bartlett <abartlet@dont-contact.us>
Date: Wed, 27 Feb 2002 19:47:29 +1100

"Chemolli Francesco (USI)" wrote:
>
> > On Monday 25 February 2002 09:53, Chemolli Francesco (USI) wrote:
> >
> > > The negotiate packet _does_ say something, there's the "flags"
> > > bitfield which defines several parameters to be used in the
> > > following phases (i.e. "I understand Unicode")
> >
> > Exacly, and is why not having it when generating the challenge packet
> > is broken. The challenge generator and the browser needs to agree on
> > the flags.
> >
> > There is at minimum two flags that is important
> > - NTLMSSP_NEGOTIATE_UNICODE (0x00000001)
> > - NTLMSSP_NEGOTIATE_NTLM2 (0x00008000)
>
> Easy: the NTLMSSP helper understands neither, so those are always reset :)
> If you're talking about future protocol extensions where the helpers might
> not see the whole picture, I agree that it wouldn't be wise.

We need to understand these to deal with any 'international' usernames.
These should then become Samba's 'unix charset' before going down the
winbind pipe. I'll look into a better way of defining this - probably
by defining the auth-crap stuff to be utf8.

Andrew Bartlett

-- 
Andrew Bartlett                                 abartlet@pcug.org.au
Manager, Authentication Subsystems, Samba Team  abartlet@samba.org
Student Network Administrator, Hawker College   abartlet@hawkerc.net
http://samba.org     http://build.samba.org     http://hawkerc.net
Received on Wed Feb 27 2002 - 01:49:55 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:14:49 MST