-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Ken Moberg wrote:
> Is there a flavor of the pam_winbind module 
> that uses Challenge/Response (CRAP) for authentication?
Nope.  Because Every PAM enabled app I'm aware of likes to use the
username/password.
> I have samba-3.0.25 and the pam_winbind module only does cleartext. 
> This fails when trying to authenticate against AD.
I"m curious why it fails for you.  Internally winbindd still
does with the Kerb5 AS_REQ or NTLM auth on behavior of the user
to AD.
> I'd like to switch our app from using ntlm_auth to pam. I
> did a quick hack an added winbind_auth_request_crap() and 
> it works, but I'm wondering if anyone else has already
> done this.
Nope.  Is this a custom app?
cheers, jerry
====================================================================Samba       
------- http://www.samba.org
Centeris                         -----------  http://www.centeris.com
"What man is a man who does not make the world better?"      --Balian
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFG1WHUIR7qMdg1EfYRAquiAKCXgmmdL5th8ZTIDhK9gIf6JLBlyQCg8o7m
uzujQrq4ZEetPpGfjxdu7Uk=fTGN
-----END PGP SIGNATURE-----