mj wrote:
I understand that the problem is larger than just packetfence, yes.

Reading your email, I'm not sure what to do NOW. Fortunately I had not
migrated all workstations to 802.1x, just a few to test stability.

However, the mailinglist (you, as well) were major advocates to move in
that direction. But it seems this has become problematic.

How 'dangerous' would it be to keep ntlm enabled?

Hi mj,
Here's an exchange between ntlm_auth's creator and I that shows my fears are exaggerated:
https://lists.samba.org/archive/samba/2016-April/199120.html

Provided you have recent, patched versions of winbind and Active-Directory the communication between FreeRADIUS and AD is secure.

So PEAP gets to live to fight another day.
Not my favorite protocol, but it just can't be deprecated yet because the more modern alternatives have not really been supported on Windows prior to Windows 8.


Regards,
--
Louis Munro
[email protected] <mailto:[email protected]> :: www.inverse.ca <http://www.inverse.ca>
+1.514.447.4918 x125  :: +1 (866) 353-6153 x125
Inverse inc. :: Leaders behind SOGo (www.sogo.nu <http://www.sogo.nu>) and PacketFence (www.packetfence.org <http://www.packetfence.org>)

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to