ChatCrawlersearch across public Telegram Open the app
L

Linus Tech Tips Discussion

сообщение · 2026-02-11 18:54 UTC
L
Ссылка
click to show
 Microsoft drops NTLM: Kerberos enters the game, Linux Loses Compatibility Summary I thought I would share this since it will affect many of us... Microsoft’s plan to retire NTLM in favour of Kerberos undeniably improves security, but it also leaves many everyday setups exposed to breakage. Linux SMB shares without full Active Directory integration, older CUPS configured / network shared printers, and legacy NAS devices will simply stop authenticating unless left open to the network. Kerberos is stronger, but its infrastructure requirements mean many home labs and small offices will feel the downside long before they see the benefits   Quotes Quote Today, NTLM is classified as deprecated. Deprecated features remain available, but no longer receive updates or enhancements and may be removed in a future release. Despite its deprecated status, NTLM continues to be prevalent in environments where modern protocols, such as Kerberos, are not feasible due to legacy dependencies, network limitations, or ingrained application logic    Quotes Quote Microsoft announced that it will disable the 30-year-old NTLM authentication protocol by default in upcoming Windows releases due to security vulnerabilities that expose organizations to cyberattacks.   My thoughts Microsoft is moving ahead with its plan to phase out NTLM and push everything toward Kerberos. From a pure security standpoint, it’s hard to argue with the logic. Kerberos is stronger, modern, and far less vulnerable to the replay and relay attacks that have plagued NTLM for years. In tightly managed enterprise environments, this shift will absolutely raise the security baseline. But outside that ideal world, the consequences are going to be painful. A lot of Linux SMB setups rely on NTLM unless they’re fully joined to Active Directory, and many home or small office servers simply aren’t. Those shares will stop authenticating unless you either rearchitect everything around AD or drop them back to unauthenticated access, which defeats the whole point of the change. Older CUPS printers that expose SMB or require NTLM for browsing or authentication will also be stranded unless you leave them open to the network.   And that’s only the obvious fallout. Expect breakage in: •     Legacy NAS devices that never received firmware updates •     Embedded systems that hardcoded NTLM years ago •     Cross platform scripts and automations that assume NTLM is always available •     Mixed Windows Linux environments where Kerberos configuration is non trivial •     Small offices that rely on simple workgroup style sharing with no domain controller Kerberos is unquestionably more secure, but it comes with prerequisites: working DNS, synchronized clocks, a domain infrastructure,

Вся лента · оригинал в Telegram

Open in Telegram Каталог площадок Искать в ChatCrawler

A snapshot of an open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog