Re: [linux-cifs-client] Linux CIFS NTLMSSP mount failing against win2k8
Andrew Bartlett <[email protected]>
| Newsgroups | gmane.network.samba.internals,gmane.linux.file-systems.cifs |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 2010-04-13 at 23:45 -0500, Shirish Pargaonkar wrote: > On Tue, Apr 13, 2010 at 6:01 PM, Andrew Bartlett <[email protected]> wrote: > > On Sun, 2010-04-11 at 19:40 -0400, Jeff Layton wrote: > > > >> I don't think that's right. CIFS_SESS_KEY_SIZE is 24 bytes. According > >> to the MS-NLMP document, the session key should be 16 bytes. The > >> signing key is different with NTLMSSP than with "raw" NTLM and NTLMv2. > > > > So, with NTLMSSP the 24 byte (actually variable, it is much lager for > > NTLMv2) response is not included in the MAC calculation - just use the > > 16 bytes session key only. > > Does this apply to both ntlm and ntlmv2 authentications because for ntlm > authentication, session key is 16 bytes but not for ntlmv2 authentication? NTLMv2 also produces a 16 byte session key, the same as all NTLM authentication variants. > I thought MAC key is generated by concatenating the smb session key > with ntlm/ntlmv2 > client response to the server challenge. It is, except that when NTLMSSP is used, the client response is omitted (the NTLMSSP layer isn't broken to get at the client response). Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org Samba Developer, Cisco Inc.
signature.asc
(application/pgp-signature, 190 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.14 (GNU/Linux) iD8DBQBLxYiPz4A8Wyi0NrsRAoqnAJ9vQryzsjyUVdxac47D2dfrOgB1EwCff2CB 70RzCx3UCzurmVz4s0vmJcY= =aZCu -----END PGP SIGNATURE-----