Re: NTLMv2 support for domain logins using freetds

"Alek Fehretdinov" <[email protected]>
Newsgroups gmane.comp.db.tds.freetds
Message-ID <[email protected]>
Freddy,

Thanks a lot for quick response. I was working all day today upgrading to
FreeTDS 0.82 (I had 0.63 before) and reinstalled DBD::Sybase
Unfortunately I am getting the same error message even after this updrade si
looks like I am missing something here, Hope you can point me on this.
Please take a look at details below:

 1. All Windows servers in our network configured with: "Send ntlm v2
response only"
2. Platforms and settings

Was FreeTDS 0.63 On Solaris 10 (SunOS 5.10) before today but I have
recompiled now with FreeTDS 0.82  (and re-installed DBD:Sybase

echo $SYBASE
/usr/local/freetds

freetds.conf:
======================================

      tds version = 8.0

      dump file = /tmp/freetds.log
      debug flags = 0xffff

      timeout = 10
      connect timeout = 10

       text size = 64512

[NYCITASD0060]
      host = NYCITASD0060.us.db.com <http://nycitasd0060.us.db.com/>
      port = 1433

========================================

3. I can successfully login using database level authentication (database
level user ID):

 $ /usr/local/freetds/bin/tsql -SNYCITASD0060  -Udb_tools -P<...pwd...>
locale is
"/en_US.ISO8859-1/en_US.ISO8859-1/C/en_US.ISO8859-1/en_US.ISO8859-1/C"
locale charset is "ISO8859-1"
1> select @@servername
2> go

NYCITASD0060
(1 row affected)

4. Now I tried to connect as user 'FIAKHAL' which belongs to domain 'DBG'

/usr/local/freetds/bin/tsql -SNYCITASD0060  -U'DBG\FIAKHAL' <domain
password>' -I./interf.conf
locale is
"/en_US.ISO8859-1/en_US.ISO8859-1/C/en_US.ISO8859-1/en_US.ISO8859-1/C"
locale charset is "ISO8859-1"
Msg 18452, Level 14, State 1, Server , Line 0
Login failed for user '(null)'. Reason: Not associated with a trusted SQL
Server connection.
Msg 20002, Level 9, State -1, Server OpenClient, Line -1
Adaptive Server connection failed
There was a problem connecting to the server

$ cat dumpconfig.log
===================================================
log.c:190:Starting log file for FreeTDS 0.82
       on 2008-07-24 17:20:40 with debug flags 0x4fff.
config.c:172:Getting connection information for [NYCITASD0060].
config.c:181:Attempting to read conf files.
config.c:253:Found conf file './interf.conf' set programmatically.
config.c:398:Looking for section global.
config.c:455:   Found section nycitasd0060.
config.c:469:   Reached EOF
config.c:398:Looking for section NYCITASD0060.
config.c:455:   Found section nycitasd0060.
config.c:458:Got a match.
config.c:479:   host = 'NYCITASD0060.us.db.com<http://nycitasd0060.us.db.com/>
'
config.c:508:Found host entry
NYCITASD0060.us.db.com<http://nycitasd0060.us.db.com/>
.
config.c:512:IP addr is 10.152.37.113.
config.c:479:   port = '1433'
config.c:469:   Reached EOF
config.c:257:Success: [NYCITASD0060] defined in ./interf.conf.
config.c:558:tds_config_login: client_charset is ISO8859-1.
config.c:195:Final connection parameters:
config.c:196:            server_name = NYCITASD0060
config.c:197:                   port = 1433
config.c:198:          major_version = 8
config.c:199:          minor_version = 0
config.c:200:             block_size = 0
config.c:201:               language = us_english
config.c:202:         server_charset =
config.c:203:        connect_timeout = 0
config.c:204:       client_host_name = nygmwsp011.us.db.com
config.c:205:               app_name = TSQL
config.c:206:              user_name = DBG\FIAKHAL
config.c:209:                library = TDS-Library
config.c:210:              bulk_copy = 0
config.c:211:      suppress_language = 0
config.c:212:          encrypt level = 0
config.c:213:          query_timeout = 0
config.c:216:         client_charset = ISO8859-1
config.c:217:                ip_addr = 10.152.37.113
config.c:218:          instance_name =
config.c:219:               database =
config.c:220:              dump_file =
config.c:221:            debug_flags = 0
config.c:222:              text_size = 0
config.c:223:           broken_dates = 0
config.c:224:           broken_money = 0
config.c:225:     emul_little_endian = 0
===================================================

Please help...!
Regards,
=Alek

On 7/24/08, ZIGLIO, Frediano, VF-IT <[email protected]> wrote:
>
> >
> > Dear freetds,
> >
> > My question is if NTLMv2 support is planned to be implemented
> > any time soon
> > in the next releases of FreeTDS. I think this is probably the one most
> > important feature that needs to be moved up in your priority
> > to-do list. I
> > was excited to see the working connections to MSSQL servers
> > from my test
> > Unix client scripts but in big firms (I work at one of them)
> > the security
> > standards will not allow to use FreeTDS facility unless it
> > supports NTLMv2
> > which is a standard security setup on most of the NT boxes in
> > such firms.
> >
>
> NTLM2 and Kerberos are implemented so you should have no problem at all.
> Which FreeTDS version are you using? Which environment setting?
>
> > I tried to google this but the results are somewhat mixed: it
> > looks like
> > this is something that is under the consideration but it's
> > still not clear
> > if I can hope to see this implemented any time soon.
> >
> > Will really appreciate any info on this.
> >
> > Regards,
> > Alek Fehretdinov
> > Deutsche Bank, New York
>
> bye
> freddy77
>
> _______________________________________________
> FreeTDS mailing list
> [email protected]
> http://lists.ibiblio.org/mailman/listinfo/freetds
>
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.