RE: [Pfif] [cifs-protocol] Clarify AEAD behaviour for GSSAPI with AES

2008-08-26 Thread Hongwei Sun
Andrew, In this case, you provided a diagram for us to add to the document and metze added some comments. Thanks for your contribution to our documentation and continued feedback. The product team reviewed the diagram and comments provided. We believe that the diagrams imply interaction

[cifs-protocol] RE: Secret 'last set times' doc incorrect in 2008 - 600578

2008-08-26 Thread Richard Guthrie
Andrew, I will be working with you to resolve your issue. I had a quick question to help with our research: If you have a secret object with old/new secret values set. They also both have a timestamp indicating when the values were last updated/set. You call LsarSetSecret passing in null

[cifs-protocol] RE: How are 'supported enc types' determined in trusts? - 600253

2008-08-26 Thread Richard Guthrie
Andrew, I will be working with you regarding this issue. I wanted to clarify your statement regarding downlevel domain. Are you referring to a windows 2008 server acting as a domain controller in a downlevel domain? I will get back to you shortly once I have completed my research. Richard

[cifs-protocol] RE: 600634 - RE: salt used for various principal types

2008-08-26 Thread Andrew Bartlett
On Tue, 2008-08-26 at 08:37 -0700, Richard Guthrie wrote: Andrew Microsoft does use different methods of calculating the salt value used in encryption depending on the type account that is submitted to the salt calculation implementation. For example, in the case of interdomain trust

[cifs-protocol] RE: How are 'supported enc types' determined in trusts? - 600253

2008-08-26 Thread Andrew Bartlett
On Tue, 2008-08-26 at 15:05 -0700, Richard Guthrie wrote: Andrew, I will be working with you regarding this issue. I wanted to clarify your statement regarding downlevel domain. Are you referring to a windows 2008 server acting as a domain controller in a downlevel domain? I will get back

[cifs-protocol] RE: 601628 RE: Mapping of MS-LSAD onto LDAP and DRS replications

2008-08-26 Thread Andrew Bartlett
On Tue, 2008-08-26 at 11:11 -0700, Richard Guthrie wrote: Andrew, The link between G$$trusted domain secrets and trustAuthIncoming is that G$$trusted domain secrets is where the password for the trust was stored prior to active directory (I.E. NT4 for example). If the trust is a trust

[cifs-protocol] RE: Secret 'last set times' doc incorrect in 2008 - 600578

2008-08-26 Thread Andrew Bartlett
On Tue, 2008-08-26 at 14:21 -0700, Richard Guthrie wrote: Andrew, I will be working with you to resolve your issue. I had a quick question to help with our research: If you have a secret object with old/new secret values set. They also both have a timestamp indicating when the values

[cifs-protocol] RE: Secret 'last set times' doc incorrect in 2008 - 600578

2008-08-26 Thread Andrew Bartlett
On Wed, 2008-08-27 at 08:50 +1000, Andrew Bartlett wrote: On Tue, 2008-08-26 at 14:21 -0700, Richard Guthrie wrote: Andrew, I will be working with you to resolve your issue. I had a quick question to help with our research: If you have a secret object with old/new secret values

RE: [cifs-protocol] What are the POLICY_DOMAIN_KERBEROS_TICKET_INFO flags?

2008-08-26 Thread Hongwei Sun
Andrew, I will be working on this request and I'll let you know when I have the information for you. Thanks ! Hongwei -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Andrew Bartlett Sent: Monday, August 25, 2008 8:31 PM To: Interoperability