summaryrefslogtreecommitdiff
path: root/docs/smbdotconf/security/clientntlmv2auth.xml
blob: b8436d72e9a68c42fd7e47fa3803c6ab4e02d0d5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
<samba:parameter name="client ntlmv2 auth"
                 context="G"
				 type="boolean"
                 advanced="1" developer="1"
                 xmlns:samba="http://samba.org/common">
<description>
    <para>This parameter determines whether or not <citerefentry><refentrytitle>smbclient</refentrytitle>
    <manvolnum>8</manvolnum></citerefentry> will attempt to
    authenticate itself to servers using the NTLMv2 encrypted password
    response.</para>

    <para>If enabled, only an NTLMv2 and LMv2 response (both much more
    secure than earlier versions) will be sent.  Many servers
    (including NT4 &lt; SP4, Win9x and Samba 2.2) are not compatible with
    NTLMv2.  </para>

    <para>Similarly, if enabled, NTLMv1, <command
    moreinfo="none">client lanman auth</command> and <command
    moreinfo="none">client plaintext auth</command>
    authentication will be disabled.  This also disables share-level 
    authentication. </para>

    <para>If disabled, an NTLM response (and possibly a LANMAN response)
    will be sent by the client, depending on the value of <command
    moreinfo="none">client lanman auth</command>.  </para>

    <para>Note that some sites (particularly
    those following 'best practice' security polices) only allow NTLMv2
	responses, and not the weaker LM or NTLM.</para>
</description>
<value type="default">no</value>
</samba:parameter>