New issue
Advanced search Search tips

Issue 807760 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Jan 2018
EstimatedDays: ----
NextAction: ----
OS: Linux , Chrome , Mac
Pri: 1
Type: Bug



Sign in to add a comment

Make NTLMv2 the default NTLM version.

Project Member Reported by zentaro@chromium.org, Jan 31 2018

Issue description

NTLMv2 was already implemented and has been available to be enabled behind a flag.

It has had a test pass on the initial release of the feature behind the flag, and multiple external third parties have validated that the feature works correctly.

NTLMv2 (which is a primarily Windows authentication method) is the default on all recent Window's version and in all other non-Chrome browsers. NTLM is considered to be insecure and is not recommended to be used.

This change makes NTLMv2 the default but for this release still leaves the flag available for users to downgrade if they choose.

The implementation was done against this bug https://bugs.chromium.org/p/chromium/issues/detail?id=22532

This bug tracks making the default NTLM. 

This is the change that makes NTLMv2 default https://chromium-review.googlesource.com/c/chromium/src/+/885509
 
Requesting to merge this CL to 65 that missed the branch point.
https://chromium-review.googlesource.com/c/chromium/src/+/885509

It changes the default value of the NTLM protocol to NTLMv2 which is consistent with all other browsers. In 64 the feature already existed and was tested behind a flag and verified internally and by external third parties.

65 will retain the flag to provide users with the behavior to downgrade to the old (insecure) behavior.
Previous communication has already been made that this change would be in M65.
Labels: M-65
Project Member

Comment 4 by sheriffbot@chromium.org, Feb 1 2018

Labels: -Merge-Request-65 Hotlist-Merge-Approved Merge-Approved-65
Your change meets the bar and is auto-approved for M65. Please go ahead and merge the CL to branch 3325 manually. Please contact milestone owner if you have questions.
Owners: cmasso@(Android), cmasso@(iOS), bhthompson@(ChromeOS), govind@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Bulk Edit:
Pls merge your change to M65 branch 3325 ASAP so we can pick it up for next M65 dev release. Thank you.
Labels: -Merge-Approved-65 merge-merged-3325
Applying "merge-merged-3325" per comment #6. Thank you for the merge.

Sign in to add a comment