NTLMv2 Authentication Not Enabled By Default

Bug #514274 reported by AsstZD
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
samba (Ubuntu)
Won't Fix
Wishlist
Unassigned

Bug Description

Binary package hint: samba

In default Karmic configuration, samba is not configured to use NTLMv2 authentication procedure, which makes impossible connecting to NT5.0-NT6.1 servers and workstations. The solution requires adding a paramer (not even present there by default) to smb.conf. Considering NTLMv2 is used in production environment since circa 2000 I think it's time to enable it by default.

Chuck Short (zulcss)
Changed in samba (Ubuntu):
importance: Undecided → Wishlist
status: New → Confirmed
Revision history for this message
Kevin Sumner (kevinsumner) wrote :

This should probably be marked higher than "wishlist". By default, Windows Vista (probably also 7) requires NTLMv2 and I think (not confirmed) Windows 2008 domain controllers require this for their shares as well.

Unless enabling v2 prevents v1 authentication, I can't think of any good reason not to enable this by default on Ubuntu (or even in upstream).

Revision history for this message
Thierry Carrez (ttx) wrote :

Reading smb.conf manpage, enabling "client ntlmv2 auth" will disable NTLMv1, client lanman auth and client plaintext auth authentication. It also disables share-level authentication.

Servers can be configured to accept NTLMv1 and NTLMv2, or just NTLMv2. Clients can be configured as well to send NTLMv1 or NTLMv2.

Changing the default will break existing working connections to servers and clients, and will break share-level authentication (used in XP). The idea is to follow samba upstream defaults where we can, and here I think we should.

Thierry Carrez (ttx)
Changed in samba (Ubuntu):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.