locked
NTLMv2 support is now ready for the none-certified OCS phones RRS feed

  • General discussion

  • Hi, :)

    some enterprises and organisation using Microsoft OCS have the need to force all client and server machines to support NTLMv2 only, for security concerns to LAN Manager and NTLMv1. Until now, it was impossible to connect the none-certified OCS phones from Snom , a Berlin based ip-phone vendor to this kind of OCS infrastructures.

    I had the luck to get hands-on the first version of Snom's OCS Edition firmware, which supports NTLMv2 now and I like to share my test results with you. If the topic is in your interest, please check out:

    NTLMv2 support is now ready for the none-certified OCS phones

    Let's play it save! ;)

    Regards,
    Jan

    Jan Boguslawski | Consultant IT Infrastructure | MCITP: EA, MCTS OCS, MCTS EXCHANGE | ITaCS Berlin | www.itacs.de
    Tuesday, October 27, 2009 10:44 PM

All replies

  • Hi, ;)

    a short update on NTLMv2 / v1 behavior in snom OCS edition firmware:

    Next firmware releases will not only include NTLMv2, also the first authentification method will be NTLMv2. It will only switch back to NTLMv1 if v2 attempts are unsuccesful.

    If it works as expected, virtually all OCS infrastructure's using snom OCS edition will profit from increased security / reliability in NTLMv2, even if its not enforced. :)

    Good Luck & Regards,
    Jan


    Jan Boguslawski | Consultant IT Infrastructure | MCITP: EA, MCTS OCS, MCTS EXCHANGE | ITaCS Berlin | www.itacs.de
    Wednesday, October 28, 2009 5:30 PM

  • Jan - would you have a release date for that firmware?

    I have some on-going 'NR' issues I believe would be helped by this release...


    Are you allowed to send it directly to me?


    Regards

    Paul Adams

    paul {dot} adams {at} firsttruck {dot} ca
    Wednesday, October 28, 2009 11:27 PM
  • Paul,

    What FW you're currently on? Latest builds fixed the NR issue. It was discrepancy betnween MS documentation and actulal code...


    Drago
    Wednesday, October 28, 2009 11:32 PM

  • Thanks Drago - seems I missed that update

    I'm using 8.2.5 - 18983


    If you have a newer version - can I ask you to e-mail it to me...


    Paul
    Thursday, October 29, 2009 4:41 AM
  • Paul,

    email me: drago @ windstream . net
    Thursday, October 29, 2009 11:38 AM