diff options
| author | Jelmer Vernooij <jelmer@samba.org> | 2003-07-05 01:50:16 +0000 | 
|---|---|---|
| committer | Jelmer Vernooij <jelmer@samba.org> | 2003-07-05 01:50:16 +0000 | 
| commit | 2f4f2890e5919e52f66ac72d572e020a9c556dba (patch) | |
| tree | b1d454df3e7185fe592a0b797bbb094ac5887efa | |
| parent | d281516d0cac8bf2455689b19556282985eac0c1 (diff) | |
| download | samba-2f4f2890e5919e52f66ac72d572e020a9c556dba.tar.gz samba-2f4f2890e5919e52f66ac72d572e020a9c556dba.tar.bz2 samba-2f4f2890e5919e52f66ac72d572e020a9c556dba.zip  | |
Update from Andrew Bartlett with documentation for
'client lanman auth' and 'client ntlmv2 auth'
(This used to be commit 60f0934a6dc7a34dad42ba86744a1e3426e99967)
| -rw-r--r-- | docs/docbook/smbdotconf/security/clientlanmanauth.xml | 28 | ||||
| -rw-r--r-- | docs/docbook/smbdotconf/security/clientntlmv2auth.xml | 26 | 
2 files changed, 54 insertions, 0 deletions
diff --git a/docs/docbook/smbdotconf/security/clientlanmanauth.xml b/docs/docbook/smbdotconf/security/clientlanmanauth.xml new file mode 100644 index 0000000000..52082f9dbf --- /dev/null +++ b/docs/docbook/smbdotconf/security/clientlanmanauth.xml @@ -0,0 +1,28 @@ +<samba:parameter name="client lanman auth" +                 context="G" +                 advanced="1" developer="1" +                 xmlns:samba="http://samba.org/common"> +<listitem> +    <para>This parameter determines whether or not <citerefentry><refentrytitle>smbclient</refentrytitle> +    <manvolnum>8</manvolnum></citerefentry> and other samba client +    tools will attempt to authenticate itself to servers using the +    weaker LANMAN password hash. If disabled, only server which support NT  +    password hashes (e.g. Windows NT/2000, Samba, etc... but not  +    Windows 95/98) will be able to be connected from the Samba client.</para> + +    <para>The LANMAN encrypted response is easily broken, due to it's +    case-insensitive nature, and the choice of algorithm.  Clients +    without Windows 95/98 servers are advised to disable +    this option.  </para> + +    <para>Disabling this option will also disable the <command +    moreinfo="none">client plaintext auth</command> option</para> + +    <para>Likewise, if the <command moreinfo="none">cleint ntlmv2 +    auth</command> parameter is enabled, then only NTLMv2 logins will be +    attempted.  Not all servers support NTLMv2, and most will require +    special configuration to us it.</para> + +    <para>Default : <command moreinfo="none">client lanman auth = yes</command></para> +</listitem> +</samba:parameter> diff --git a/docs/docbook/smbdotconf/security/clientntlmv2auth.xml b/docs/docbook/smbdotconf/security/clientntlmv2auth.xml new file mode 100644 index 0000000000..4e60613a3e --- /dev/null +++ b/docs/docbook/smbdotconf/security/clientntlmv2auth.xml @@ -0,0 +1,26 @@ +<samba:parameter name="ntlmv2 auth" +                 context="G" +                 advanced="1" developer="1" +                 xmlns:samba="http://samba.org/common"> +<listitem> +    <para>This parameter determines whether or not <citerefentry><refentrytitle>smbclient</refentrytitle> +    <manvolnum>8</manvolnum></citerefentry> will attempt to +    authenticate itself to servers using the NTLMv2 encrypted password +    response.</para> + +    <para>If enabled, only an NTLMv2 and LMv2 response (both much more +    secure than earlier versions) will be sent.  Many servers +    (including NT4 < SP4, Win9x and Samba 2.2) are not compatible with +    NTLMv2.  </para> + +    <para>If disabled, an NTLM response (and possibly a LANMAN response) +    will be sent by the client, depending on the value of <command +    moreinfo="none">client lanman auth</command>.  </para> + +    <para>Note that some sites (particularly +    those following 'best practice' security polices) only allow NTLMv2 +    responses, and not the weaker LM or NTLM.</para> + +    <para>Default : <command moreinfo="none">ntlmv2 auth = no</command></para> +</listitem> +</samba:parameter>  | 
