Re: [Samba] Daily changetrustpw breaks authentication

This is a discussion on Re: [Samba] Daily changetrustpw breaks authentication within the Samba forums, part of the Networking and Network Related category; --===============0510242972== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-p3Z26sMANr/iDg3mfNdt" --=-p3Z26sMANr/...


Go Back   Usenet Forums > Networking and Network Related > Samba

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-17-2006
Andrew Bartlett
 
Posts: n/a
Default Re: [Samba] Daily changetrustpw breaks authentication


--===============0510242972==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="=-p3Z26sMANr/iDg3mfNdt"


--=-p3Z26sMANr/iDg3mfNdt
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Wed, 2006-03-15 at 16:59 -0600, Jim Moser wrote:
> Anyone have any thoughts on this? Is changetrustpw even required? Are=20
> other people using it with success?


No, it's not required (but perhaps a good security idea). =20

Samba 3.0 sets the 'password does not expire' bit when joining, and
doesn't change the password, particularly against AD. =20

Samba 3.0 doesn't store the previous password, so in some situations we
could break due to changing the password on one, while still talking to
a different server. This creates a race, where we correctly detect that
something broke the credentials chain, but can't correctly set it up
again.

(Samba4 doesn't yet use the previous password either, but stores it).

Doing the change daily seems overkill to me, and creates a greater
chance of the race.=20

I hope that clarifies things a bit better.

Andrew Bartlett

--=20
Andrew Bartlett http://samba.org/~abartlet/
Authentication Developer, Samba Team http://samba.org
Student Network Administrator, Hawker College http://hawkerc.net

--=-p3Z26sMANr/iDg3mfNdt
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQBEGgYaz4A8Wyi0NrsRAqUiAJ9CCMxbuheszOHxBeX9JG vxlU7byACfWuKL
UYlYfgxIqFSCGrTlmAV0FY4=
=4Fk6
-----END PGP SIGNATURE-----

--=-p3Z26sMANr/iDg3mfNdt--


--===============0510242972==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
To unsubscribe from this list go to the following URL and read the
instructions: https://lists.samba.org/mailman/listinfo/samba
--===============0510242972==--

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:52 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0