SMB signing problem

Diego Woitasen diego at woitasen.com.ar
Fri May 20 11:53:24 EDT 2011


On Fri, May 20, 2011 at 8:27 AM, Martin Schweizer <
schweizer.martin at gmail.com> wrote:

> Hello Diego
>
> There is an option in the group policies where you can deactivate such
> thing. I attached you print screen where you see the policy (but only
> in german, but I see the postion).
>
> Regards,
>
>
> 2011/5/19 Diego Woitasen <diego at woitasen.com.ar>:
>  > Hi,
> >  I've been using SASL NTLM auth with Cyrus IMAP and Postfix for months
> > without any problem. The servers was Windows 2000 until the last weekend
> > because our customer upgraded to 2003. After that, NTLM stopped working.
> The
> > error in imapd.log is "NTLM: error in NEGPROT response parameters".
> > I think that this problem is related to "Default Domain Controller policy
> > has Server Message Buffering (SMB) signing". There is a report about this
> on
> > Mc Afee Product Knowledge Base with the same error. This reports says
> that
> > you should disable that policy in the Windows server but our client
> doesn't
> > like that.
> > Is there a way to fix or to work around this? I read the Cyrus SASL code
> >  but I don't see any option involved near the error message.
> > Regards,
> >  Diego
> >
> > --
> > Diego Woitasen
> >
>
>
>
> --
> Martin Schweizer
> schweizer.martin at gmail.com
>



Thanks Martin. The problem is that our client doesn´t want to change that
policy. I asked because may be there is something to do Cyrus SASL.


-- 
Diego Woitasen
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.andrew.cmu.edu/pipermail/cyrus-sasl/attachments/20110520/3e72d2e5/attachment.html 


More information about the Cyrus-sasl mailing list