git/list[1] front-page[2] threads[3] people[4] search[5] about
 

RE: [PATCH] http(s): automatically try NTLM authentication first

From
DTDavid Turner <david.turner@twosigma.com>
Date
Feb 23, 2017, 01:03 UTC
Message-ID
<b152fad7e79046c5aa6cac9e21066c1c@exmbdft7.ad.twosigma.com>
In-Reply-To
<20170222233419.q3fxqmrscosumbjm@genre.crustytoothpaste.net>
Show 20 quoted lines
> -----Original Message-----
> From: brian m. carlson [mailto:sandals@crustytoothpaste.net]
> 
> This is SPNEGO.  It will work with NTLM as well as Kerberos.
> 
> Browsers usually disable this feature by default, as it basically will attempt to
> authenticate to any site that sends a 401.  For Kerberos against a malicious
> site, the user will either not have a valid ticket for that domain, or the user's
> Kerberos server will refuse to provide a ticket to pass to the server, so
> there's no security risk involved.
> 
> I'm unclear how SPNEGO works with NTLM, so I can't speak for the security
> of it.  From what I understand of NTLM and from RFC 4559, it consists of a
> shared secret.  I'm unsure what security measures are in place to not send
> that to an untrusted server.
> 
> As far as Kerberos, this is a desirable feature to have enabled, with little
> downside.  I just don't know about the security of the NTLM part, and I don't
> think we should take this patch unless we're sure we know the
> consequences of it.
NTLM on its own is bad:

https://msdn.microsoft.com/en-us/library/windows/desktop/aa378749(v=vs.85).aspx says:

"
1. (Interactive authentication only) A user accesses a client computer and 
provides a domain name, user name, and password. The client computes a 
cryptographic hash of the password and discards the actual password.
2. The client sends the user name to the server (in plaintext).
3. The server generates a 16-byte random number, called a challenge or 
nonce, and sends it to the client.
4. The client encrypts this challenge with the hash of the user's password 
and returns the result to the server. This is called the response.
..."

Wait, what? If I'm a malicious server, I can get access to an offline oracle for whether I've correctly guessed the user's password? That doesn't sound secure at all! Skimming the SPNEGO RFCs, there appears to be no mitigation for this.

So, I guess, this patch might be considered a security risk. But on the other hand, even *without* this patch, and without http.allowempty at all, I think a config which simply uses a https:// url without the magic :@ would try SPNEGO. As I understand it, the http.allowempty config just makes the traditional :@ urls work.

Actually, though, I am not sure this is as bad as it seems, because gssapi might protect us. When I locally tried a fake server, git (libcurl) refused to send my Kerberos credentials because "Server not found in Kerberos database". I don't have a machine set up with NTLM authentication (because, apparently, that would be insane), so I don't know how to confirm that gssapi would operate off of a whitelist for NTLM as well.

Previous: Jeff KingNext: brian m. carlson
Message 17 of 38 in “http(s): automatically try NTLM authentication first”
  1. http(s): automatically try NTLM authentication firstDavid Turner, Feb 22, 2017
  2. Junio C HamanoFeb 22, 2017
  3. David TurnerFeb 22, 2017
  4. Junio C HamanoFeb 22, 2017
  5. Jeff KingFeb 22, 2017
  6. Johannes SchindelinFeb 23, 2017
  7. Junio C HamanoFeb 23, 2017
  8. Jeff KingFeb 23, 2017
  9. Junio C HamanoFeb 23, 2017
  10. Jeff KingFeb 23, 2017
  11. Johannes SchindelinFeb 25, 2017
  12. brian m. carlsonFeb 22, 2017
  13. Jeff KingFeb 22, 2017
  14. Junio C HamanoFeb 23, 2017
  15. Junio C HamanoFeb 23, 2017
  16. Jeff KingFeb 23, 2017
  17. David TurnerFeb 23, 2017
  18. brian m. carlsonFeb 23, 2017
  19. Mantas MikulėnasFeb 23, 2017
  20. Jeff KingFeb 22, 2017
  21. Junio C HamanoFeb 22, 2017
  22. Jeff KingFeb 22, 2017
  23. Junio C HamanoFeb 22, 2017
  24. Jeff KingFeb 22, 2017
  25. Junio C HamanoFeb 22, 2017
  26. Jeff KingFeb 22, 2017
  27. 2/2 http: add an "auto" mode for http.emptyauthJeff King, Feb 22, 2017
  28. David TurnerFeb 23, 2017
  29. Jeff KingFeb 23, 2017
  30. David TurnerFeb 23, 2017
  31. Jeff KingFeb 23, 2017
  32. David TurnerFeb 23, 2017
  33. Johannes SchindelinFeb 25, 2017
  34. Jeff KingFeb 25, 2017
  35. http: add an "auto" mode for http.emptyauthJeff King, Feb 25, 2017
  36. Junio C HamanoFeb 27, 2017
  37. Johannes SchindelinFeb 28, 2017
  38. 1/2 http: restrict auth methods to what the server advertisesJeff King, Feb 22, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.