RE: Kerberos and NTLM Authentication protocol

From: David Schenz (schenz.9_at_osu.edu)
Date: 11/11/04

  • Next message: Roger A. Grimes: "RE: Kerberos and NTLM Authentication protocol"
    To: "'. .'" <chirobado@hotmail.com>, <security-basics@securityfocus.com>
    Date: Wed, 10 Nov 2004 21:35:18 -0500
    
    

    Yes.

    The theoretical reason, of course, is security in depth. First, NTLM is used
    every day in a network, even in a Win2k+ domain with 2k+ clients for
    authentication to cifs shares via ip address, authentication to websites
    (depending on configuration), authentication when time differences are too
    great for Kerberos, or cross forest authentication (I think). A network is
    not a static thing either. People bring in their own laptops and computers
    which in an ideal world would be running a so called 'modern' os.
    Unfortunately, that ideal world is usually not the case. In larger
    environments, the person who creates the gpo does not necessarily control
    which computers are brought into a network. All of these scenarios
    illustrate why LMCompatability level needs to be set to NTLMv2 only.

    HTH,
    David

    -----Original Message-----
    From: . . [mailto:chirobado@hotmail.com]
    Sent: Wednesday, November 10, 2004 5:33 PM
    To: security-basics@securityfocus.com
    Subject: Kerberos and NTLM Authentication protocol

    In a domain with DC 2003 and clients all windows 2000 and XP:

    * ¿Is there any important reason to change de LMCompatibility level to
    prevent using LM/NTLM and use only NTLMv2 in both clients and DCs?

    As far as I know, in this enviroment, authentication agains DC is set
    through Kerberos v5. Keberos uses the NT Hash, but no NTLM authentication
    protocol at all.

    If there is no case where NTLM or LM authentication protocol is needed (it
    would be needed just between clients, but no w9x or nt clients in the
    network)... is there any reason to be "worried"?

    Thanks.

    _________________________________________________________________
    Un amor, una aventura, compañía para un viaje. Regístrate gratis en MSN Amor

    & Amistad. http://match.msn.es/


  • Next message: Roger A. Grimes: "RE: Kerberos and NTLM Authentication protocol"

    Relevant Pages

    • Re: IP address assignment problem
      ... I have a little problem and seek for ur thoughts, let's assume I'm in a very open environment where everyone can very easily try to get his/her laptop on the network and IP addresses are assigned by a DHCP server and we are in a domain environment, how do I prevent machines that are not part of our domain to be assigned an IP address? ... This approach doesn't stop your rogue clients from connecting to other clients, but merely doesn't give them the information they normally need to do so. ... Using 802.1x, your workstations authenticate through the switch to a radius server before they are allowed any connectivity. ... This authentication can use X.509 certificates, computer account credentials from AD, or whatever else you'd normally configure radius to authenticate with. ...
      (Focus-Microsoft)
    • Re: Remote site BDCs wont auth clients when T1 to AD 2003 is down LTLM?
      ... Depending on what clients you have if you do not have additional W2K DCs ... Put a W2K DC at every site the you want authentication to continue if the ... 298713 How to Prevent Overloading on the First Domain Controller During ... I have tried forcing the AD controller to do NTLM only- but that ...
      (microsoft.public.security)
    • Re: Remote site BDCs wont auth clients when T1 to AD 2003 is down LTLM?
      ... Depending on what clients you have if you do not have additional W2K DCs ... Put a W2K DC at every site the you want authentication to continue if the ... 298713 How to Prevent Overloading on the First Domain Controller During ... I have tried forcing the AD controller to do NTLM only- but that ...
      (microsoft.public.win2000.security)
    • Re: Event log shows NTLM not Kerberos
      ... so this is for a network login. ... Authentication Package: NTLM ... Authentication Package NTLM not Kerberos? ...
      (microsoft.public.security)
    • Re: LM or NTLMv1 or NTLMv2
      ... The MSV1_0 authentication package implements the ... different LM and NTLM versions. ... Except by capturing the network traffic that occurs when SMB session are ...
      (microsoft.public.win2000.security)