RE: Kerberos and NTLM Authentication protocol

From: Roger A. Grimes (roger_at_banneretcs.com)
Date: 11/11/04

  • Next message: Alex V. Lukyanenko: "Re: DHCP scanning"
    Date: Wed, 10 Nov 2004 23:02:47 -0500
    To: ". ." <chirobado@hotmail.com>, <security-basics@securityfocus.com>
    
    

    There is always a reason why something other than Kerberos must be used for Windows authentication. Kerberos can't be used for dozens of things, including: local logins, legacy trusts, Cluster authentication, anytime UDP RPC is used, RRAS logins, etc.

    And you will always need local logins. Besides the local admin account, local logins are used by services and a myriad of other processes behind the scenes.

    So, NTLMv2 (or NTLM or LM) can't not be used. It can't be turned off. Windows will always need a "legacy" auth protocol, so if it has to be used, making Windows use NTLMv2 instead of LM or NTLM is a good thing to do.

    Roger

    ***************************************************************************
    *Roger A. Grimes, Banneret Computer Security, Computer Security Consultant
    *CPA, CISSP, MCSE: Security (NT/2000/2003/MVP), CNE (3/4), A+
    *email: roger@banneretcs.com
    *cell: 757-615-3355
    *Author of Malicious Mobile Code: Virus Protection for Windows by O'Reilly
    *http://www.oreilly.com/catalog/malmobcode
    *Author of upcoming Honeypots for Windows (Apress)
    ****************************************************************************

    -----Original Message-----
    From: . . [mailto:chirobado@hotmail.com]
    Sent: Wednesday, November 10, 2004 5:33 PM
    To: security-basics@securityfocus.com
    Subject: Kerberos and NTLM Authentication protocol

    In a domain with DC 2003 and clients all windows 2000 and XP:

    * ¿Is there any important reason to change de LMCompatibility level to prevent using LM/NTLM and use only NTLMv2 in both clients and DCs?

    As far as I know, in this enviroment, authentication agains DC is set through Kerberos v5. Keberos uses the NT Hash, but no NTLM authentication protocol at all.

    If there is no case where NTLM or LM authentication protocol is needed (it would be needed just between clients, but no w9x or nt clients in the network)... is there any reason to be "worried"?

    Thanks.

    _________________________________________________________________
    Un amor, una aventura, compañía para un viaje. Regístrate gratis en MSN Amor & Amistad. http://match.msn.es/


  • Next message: Alex V. Lukyanenko: "Re: DHCP scanning"

    Relevant Pages

    • Re: Change in ASP.Net authentication between Win2000 and Win2003
      ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
      (microsoft.public.windows.server.security)
    • Re: Change in ASP.Net authentication between Win2000 and Win2003
      ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
      (microsoft.public.inetserver.iis.security)
    • cross-realm authentication problem
      ... I am trying to get cross-realm authentication to work between AD and our MIT Kerberos realm. ... Windows client are in KLIENT.UIB.NO, Windows user accounts are in UIB.NO, Unix/Linux machines and accounts are in UNIX.UIB.NO. ... After choosing UNIX.UIB.NO as authentication domain on a Windows machine Kerberos negotiation works fine. ... But using a Windows machine where the user is authenticated in UIB.NO I get cross-realm authentication only to the web server running RHEL4, not the one running RHEL5, I never even get a ticket for UNIX.UIB.NO from AD when trying to access the RHEL5 server web page. ...
      (comp.protocols.kerberos)
    • Re: Kerberos authentication NOT in AD
      ... I'm not sure where the piece of code is that gives you a high level Kerberos ... Windows to do it yourself, but I'm not an expert at this. ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... so I'm not doing any authentication as of yet (I've ...
      (microsoft.public.dotnet.security)
    • Re: Kerberos login on VMS
      ... Does the latest version of Pathworks support either Kerberos or LDAP ... NTLM authentication? ... >OpenVMS System Software Group ... Any version of Windows server more recent than Windows NT ...
      (comp.os.vms)

  • Quantcast