From: Arne Schwabe Date: Thu, 15 Dec 2022 19:01:43 +0000 (+0100) Subject: Deprecate NTLMv1 proxy auth method. X-Git-Tag: v2.7_alpha1~634 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e005b8d1fda1ad1e26fe0dbe7e09184a1f19b553;p=thirdparty%2Fopenvpn.git Deprecate NTLMv1 proxy auth method. NTLMv1 is ancient and not considered secure anymore and we are not aware of any users or software still requiring this feature. Additionally it currently depends on our "doing single DES using 3DES" workaround for OpenSSL (cipher_des_encrypt_ecb). So removing NTLMv1 will also allow us to remove that workaround. Reported-By: Trial of Bits (TOB-OVPN-7) Signed-off-by: Arne Schwabe Acked-by: Gert Doering Message-Id: <20221215190143.2107896-9-arne@rfc2549.org> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg25731.html Signed-off-by: Gert Doering --- diff --git a/src/openvpn/proxy.c b/src/openvpn/proxy.c index ed7201616..633caee09 100644 --- a/src/openvpn/proxy.c +++ b/src/openvpn/proxy.c @@ -519,6 +519,8 @@ http_proxy_new(const struct http_proxy_options *o) #if NTLM else if (!strcmp(o->auth_method_string, "ntlm")) { + msg(M_INFO, "NTLM v1 authentication is deprecated and will be removed in " + "OpenVPN 2.7"); p->auth_method = HTTP_AUTH_NTLM; } else if (!strcmp(o->auth_method_string, "ntlm2"))