NTLM has been a security liability for decades, yet it remains deeply embedded in enterprise environments. Its weaknesses are well documented: relay attacks, pass-the-hash, weak cryptography, you name it.
Microsoft has announced plans to deprecate NTLM, and announced to use IAKerb the successor, that works across heterogeneous environments.
In this talk Andreas Schneider and Alexander Bokovoy (both Red Hat / Samba Team) present a concrete approach to eliminating NTLM from SMB authentication using a local Kerberos Key Distribution Center (KDC) combined with the IAKerb extension. They demonstrate how a localkdc can serve as an authentication bridge, enabling Kerberos authentication even in scenarios where traditional KDC infrastructure is unavailable or impractical.
The talk covers the architecture of the localkdc, its integration with SSSD and Samba, and show live demonstrations of NTLM-free SMB authentication. Additionally, they explore how this approach enables OAuth 2.0 identity providers to be mapped to local POSIX identities, providing a path toward modern authentication in traditional Unix/Linux environments.
Slides: https://sambaxp.org/fileadmin/user_up...
Visit the conference website at: https://sambaxp.org
sambaXP is organised by SerNet: https://sernet.com