All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Christopher R. Hertel" <crh@ubiqx.mn.org>
To: Jeremy Allison <jra@samba.org>
Cc: Steve French <smfrench@gmail.com>,
	Dominic Dougherty <dominic.dougherty@protegrity.com>,
	"samba-technical@lists.samba.org"
	<samba-technical@lists.samba.org>,
	linux-cifs@vger.kernel.org
Subject: Re: encryption on network
Date: Thu, 28 Jul 2011 19:26:48 -0500	[thread overview]
Message-ID: <4E31FE48.7060606@ubiqx.mn.org> (raw)
In-Reply-To: <20110729001133.GA6742@jeremy-laptop>

Jeremy Allison wrote:
:
>> Right, but the question particularly listed WinXP as one of the
>> participating clients.  Windows clients don't support the Unix extensions,
>> so they don't support encrypted SMB and that kinda ruins the whole thing,
>> eh?  [sad face]
> 
> Yes I realize that. But that's not what you said. You said:
> "The SMB protocol does not provide any mechanism for encrypting traffic
> between clients and servers." - but that's not generically true,
> only between *Microsoft* clients and servers.

Well... technically the SMB protocol (as it exists today) is defined by the
Microsoft specifications, and they don't include any support for encryption.

There is, unfortunately, no "official" specification of the Unix extensions
for SMB (only an old draft that doesn't include encryption, IIRC).  Also, as
their name suggests, they're extensions to the protocol which means that
they're not part of the protocol itself.

> You made it sound like that was definitive, and you are the
> acknowledged authority on CIFS/SMB, so I couldn't let that
> stand. People link to your posts here :-).

Absolutely right to set the record straight.  I should have added the caveat
that the Unix extensions include support for encryption.

>> Please allow me to join the choir on that.  (I'll sit at the back and not
>> get in anyone's way.)  [winky face]
> 
> Maybe if we all wish REALLY HARD, Steve and Jeff will hear
> us.. :-).

Don't forget to click your heels together and burn the tana leaves when the
moon is full over Vermont.  ;)

Chris -)-----

-- 
"Implementing CIFS - the Common Internet FileSystem" ISBN: 013047116X
Samba Team -- http://www.samba.org/     -)-----   Christopher R. Hertel
jCIFS Team -- http://jcifs.samba.org/   -)-----   ubiqx development, uninq.
ubiqx Team -- http://www.ubiqx.org/     -)-----   crh@ubiqx.mn.org
OnLineBook -- http://ubiqx.org/cifs/    -)-----   crh@ubiqx.org

  reply	other threads:[~2011-07-29  0:26 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <06B0D589A4AC0243AD95D4DA4978081A182DE84D@mbx024-e1-nj-6.exch024.domain.local>
     [not found] ` <4E31E9DD.2060604@ubiqx.mn.org>
2011-07-28 23:54   ` encryption on network Jeremy Allison
2011-07-29  0:08     ` Christopher R. Hertel
     [not found]       ` <4E31F9E4.2030004-jFlgvBokg3lg9hUCZPvPmw@public.gmane.org>
2011-07-29  0:14         ` Jeremy Allison
2011-07-29  0:26           ` Christopher R. Hertel [this message]
     [not found]             ` <4E31FE48.7060606-jFlgvBokg3lg9hUCZPvPmw@public.gmane.org>
2011-07-29  1:23               ` Steve French
2011-07-29  2:11                 ` Dominic Dougherty
2011-07-29  2:34                   ` Christopher R. Hertel
     [not found]                     ` <4E321C18.5000201-jFlgvBokg3lg9hUCZPvPmw@public.gmane.org>
2011-07-29  4:04                       ` Dominic Dougherty
2011-07-29 13:25                     ` simo
2011-07-29 10:16           ` Jeff Layton
     [not found]             ` <20110729061610.59f282a8-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2011-07-29 16:34               ` Jeremy Allison

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4E31FE48.7060606@ubiqx.mn.org \
    --to=crh@ubiqx.mn.org \
    --cc=dominic.dougherty@protegrity.com \
    --cc=jra@samba.org \
    --cc=linux-cifs@vger.kernel.org \
    --cc=samba-technical@lists.samba.org \
    --cc=smfrench@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.