LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-01-2001, 08:47 AM   #1
bfloeagle
Member
 
Registered: Jun 2000
Location: Upstate New York
Distribution: Ubuntu
Posts: 158

Rep: Reputation: 30
Question PAM - Secure or Cleartext?


I am trying to research SAMBA and PAM for the company I work for. They want to use Samba as a file server for our storage with the usernames and passwords controlled via NT. I know that Samba can use PAM to try the passwords from the NT Domain Controllers (it can do this, right?) but I do not know how the information is transferred. Cleartext is a major problem here and I need to know how PAM does what it does...

Does PAM use cleartext by default? If it does, can I force it to encrypt the password?

Thanks!
Andy
 
Old 11-05-2001, 11:05 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I don't do SMB, but IIRC there are 2 ways to get auth'ed: the NT/LM and UNIX type. NTLM is (again,IIRC) encrypted because NT doesnt like unsigned authentication, while UNIX is cleartext.

Since there are no more reactions here, maybe you should try the ppl at an NG, maybe sorta like smb.protocols.(something).
 
Old 11-05-2001, 11:15 AM   #3
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
you can force password encryption in the /etc/smb.conf file with

encrypt password = yes

i'm not sure what the protocol is tho...

man smb.conf sez

encrypt passwords (G)

This boolean controls whether encrypted passwords
will be negotiated with the client. Note that Win*
dows NT 4.0 SP3 and above and also Windows 98 will
by default expect encrypted passwords unless a reg*
istry entry is changed. To use encrypted passwords
in Samba see the file ENCRYPTION.txt in the Samba
documentation directory docs/ shipped with the
source code.

In order for encrypted passwords to work correctly
smbd must either have access to a local smbpasswd
(5) file (see the smbpasswd (8) program for infor*
mation on how to set up and maintain this file), or
set the security= parameter to either "server" or
"domain" which causes smbd to authenticate against
another server.


so i'd guess it's encrypted PAM
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VSFTPD with secure & non-secure logins Ricci Graham Linux - Software 6 02-24-2020 11:49 PM
CUPS + smb: Cleartext passwords: Can they be hidden? haertig Linux - Networking 0 11-08-2005 05:05 PM
phpmyadmin & cleartext controlpass [GOD]Anck Linux - Security 3 01-26-2005 01:57 PM
vsftpd + pam + virtual users - Pam cannot load database file. mdkelly069 Linux - Networking 3 09-22-2004 11:07 PM
ldap cleartext authentication Clemente Linux - Software 0 09-18-2003 03:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:57 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration