Re: NTLM and OpenLDAP
Simo Sorce <[email protected]> Wed, 02 Mar 2022 12:24:11 -0500
| Newsgroups | gmane.comp.security.cyrus.sasl |
|---|---|
| Organization | Red Hat |
| Message-ID | <[email protected]> |
On Wed, 2022-03-02 at 11:20 -0500, Marc Boorshtein wrote: > >=20 > >=20 > >=20 > > the NTLM plugin in cyrus-sasl is an old broken custom > > implementation of > > NTLM. It used a dirty hack to try to replay the NTLM authentication > > against an SMB server (using old skeleton SMB 1 implementation > > which > > uses a SMB dialect now disabled on most servers) as a way to > > support > > authenticating against a separate server. This kind of > > authentication > > hijack will not work with any modern setup. > >=20 > >=20 > Let's assume for the sake of argument that SMB1 is still enabled > (like I > said, this is a REALLY legacy environment), would what I'm trying > still not > work? It depends on the DC, and the client, if the client or the DC wants a MIC on the NTLMSSP exchange, this will fail because the MITM (your server) will break it. Simo. --=20 Simo Sorce RHEL Crypto Team Red Hat, Inc ------------------------------------------ Cyrus: SASL Permalink: https://cyrus.topicbox.com/groups/sasl/Tac2134087a4e755f-Mc81ae0= d2866f2503c02fdedc Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription