All of lore.kernel.org
 help / color / mirror / Atom feed
From: Suresh Jayaraman <sjayaraman-IBi9RG/b67k@public.gmane.org>
To: Jeff Layton <jlayton-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
Cc: smfrench-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org,
	linux-cifs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
Subject: Re: default security mechanism for 3.1
Date: Fri, 23 Sep 2011 19:24:22 +0530	[thread overview]
Message-ID: <4E7C8F8E.2040704@suse.com> (raw)
In-Reply-To: <20110923094321.1e848857-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>

On 09/23/2011 07:13 PM, Jeff Layton wrote:
> On Fri, 23 Sep 2011 17:55:05 +0530
> Suresh Jayaraman <sjayaraman-IBi9RG/b67k@public.gmane.org> wrote:
> 
>> On 09/23/2011 05:46 PM, Jeff Layton wrote:
>>> A printk warning was added to the kernel about the default security
>>> mode changing in 3.1. As best I can tell though, that has not happened
>>> even though the release is imminent. Are you still planning to change
>>> that? If not, are you planning to fix the printk?
>>>
>>
>> Did you mean this one?
>>    http://www.spinics.net/lists/linux-cifs/msg03976.html
>>
>> I remember Steve posted this patch sometime ago but I'm not seeing them
>> in the cifs development tree..
> 
> Yeah, that's the one. Seems a little late to be adding these sorts of
> behavior changes in 3.1 though, so I'm just wondering what the plan is.
> 
> I also have some concerns about defaulting to raw NTLMv2 auth since (at
> least) win2k8 rejects unless you go in and tweak registry keys. It

Good point. May be we should just drop those warning messages for 3.1
and work on aim to make the sec_mode overhaul work for 3.2.. and
document the new behavior?

> would seem to me to be better to decide the default based on the
> negotiation:
> 
> Set extended security bit in the NegProt by default
> 
> If the server sets it, then use NTLMSSP
> 
> If it doesn't then use old NTLM (or NTLMv2)
> 
> That means an overhaul of how sec_mode is handled though, since that's
> currently decided too early to do it that way.
> 

-Suresh

  parent reply	other threads:[~2011-09-23 13:54 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-09-23 12:16 default security mechanism for 3.1 Jeff Layton
     [not found] ` <20110923081620.40c0aa17-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2011-09-23 12:25   ` Suresh Jayaraman
     [not found]     ` <4E7C7AA1.2060402-IBi9RG/b67k@public.gmane.org>
2011-09-23 13:43       ` Jeff Layton
     [not found]         ` <20110923094321.1e848857-9yPaYZwiELC+kQycOl6kW4xkIHaj4LzF@public.gmane.org>
2011-09-23 13:54           ` Suresh Jayaraman [this message]
2011-09-23 15:14           ` Shirish Pargaonkar
     [not found]             ` <CADT32e+KDBM=_jOm4m0cirQGeO7YfH4RADb5fbv7dcvUGG9j+A-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2011-09-23 15:26               ` Jeff Layton
     [not found]                 ` <CAH2r5mv1+66fxESK85+HRaRUyK_bRgzSO9tMZFoC1FiDu60zfA@mail.gmail.com>
     [not found]                   ` <CAH2r5mv1+66fxESK85+HRaRUyK_bRgzSO9tMZFoC1FiDu60zfA-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2011-09-23 19:21                     ` Jeff Layton
2011-10-06 18:00           ` Steve French

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4E7C8F8E.2040704@suse.com \
    --to=sjayaraman-ibi9rg/b67k@public.gmane.org \
    --cc=jlayton-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
    --cc=linux-cifs-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
    --cc=smfrench-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.