OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Rocky Stefano (rstefanoechelonsystems.com)
Date: Tue Oct 02 2001 - 09:54:17 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    NTLMv2 is what you should use in a mixed W2K/NT4 domain. If all your clients
    are W2K you should use Kerberos authentication which is native in W2K. One
    caveat to this is RAS. Even if you are running a native W2K forest/domain
    and are using Kerboros anyone using RAS to dialin still has to use NTVLM to
    authenticate. PSS has said it will stay like this for AWHILE

    -----Original Message-----
    From: Kevin and Laura Brown [mailto:2brownfoxhome.com]
    Sent: October 1, 2001 10:05 PM
    To: Focus on MicroSoft
    Subject: NTLM

    What are the security implications of using NTLM? Is NTLM encrypted? What
    are the alternatives in a Win2K environment (meaning native to the OS. I'm
    not interested in solutions like smart cards for my current needs)? What
    are the pros and cons of using NTLM vs other Win2K authentication schemes?

    Basically, I'm trying to determine if NTLM is the best course of action for
    securing remote user authentication in a Win2K LAN for services such as
    telnet. Also, which services can use NTLM? I know this is a lot of
    questions, and I plan on reading the technet site for a better understanding
    of how it works, but I wanted to get some professional opinions on its
    effectiveness.

    Thanks in advance,
    Brownfox