Disable NTLM on W2k

From: Thomas Kerbl (t.kerbl_at_weigl.de)
Date: 01/15/04

  • Next message: Gillo, Wayne: "RE: Disable NTLM on W2k"
    Date: Thu, 15 Jan 2004 11:32:06 +0100
    To: focus-ms@securityfocus.com
    
    

    hello ms-group,

    I want to enable the telnet Service on a Windows 2000 machine WITHOUT
    NTLM... Therefor I changed the registry value
    HKEY_LOCAL_MACHINE/Software/Microsoft/Telnet Server/1.0/NTLM from 2 to
    0... this should disable NTLM... still I get this

    <cite>
    Server allows NTLM authentication only
    Server has closed connection
    </cite>

    message when I try to connect with "telnet x.x.x.x" from another Win2k
    machine... I expected to get an login screen... I restartet the service
    and afterwards even the computer, still no effect...

    can anyone give a pointer, where the problem may be hidden?

    tia,
    Thomas

    P.S.: Just to make sure, I'm perfectly aware of the security risk... no
    advice needed :)

    -- 
    ~ weigl interservice
    ~ www.weigl.de
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Gillo, Wayne: "RE: Disable NTLM on W2k"

    Relevant Pages

    • Re: Integrated Windows Authentication Timeout?
      ... Do you see anything different for the NTLM requests? ... You might consider enabling protocol transition authentication since you are ... Joe Kaplan-MS MVP Directory Services Programming ... server. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: Integrated Windows Authentication Timeout?
      ... Is it possible that a different host name is being used for one of the subsequent requests that would break Kerberos auth? ... If you have "Negotiate" authentication set in the metabase, then this can still negotiate down to NTLM if for some reason the protocol thinks that Kerberos is unavailable. ... server. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • RE: "The page cannot be displayed" for non domain users
      ... The Wfetch utility is able to get true. ... The first atemp returns the page I get in the IE. ... When I use IE I never get the NTLM authentication window: ... Server: Microsoft-IIS/6.0\r\n ...
      (microsoft.public.inetserver.iis.security)
    • Re: IIS6, Integrated Windows Auth, and IE6 Integrated Windows Auth
      ... on your server, modifying its behavior, and causing the issue. ... do you feel that there is an issue with NTLM ... > application -- after IIS has successfully authenticated with NTLM -- so it ... > is an application issue and not with IIS6, Integrated Authentication, nor ...
      (microsoft.public.inetserver.iis)
    • RE: sshd for windows
      ... >NTLMv2 is an encryption method. ... Microsoft Telnet uses NTLM to encrypt the ... This means the only client that can access the server is the ... What’s NTLM? ...
      (Security-Basics)