public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* thousands of NTLM requests per day
@ 2017-02-28 15:17 Andrew Schulman
  2017-02-28 16:35 ` Andrey Repin
  0 siblings, 1 reply; 3+ messages in thread
From: Andrew Schulman @ 2017-02-28 15:17 UTC (permalink / raw)
  To: cygwin

I got a call from our domain admins, asking me if I knew why my Windows 7
host would be sending many thousands of NTLMv1 authentication requests per
day. I don't know, and we're still trying to find out which application is
doing that, but here's what I wonder:

Could Cygwin be responsible for the authentication requests? I wonder about
this because Cygwin now queries Windows for user and group information that
used to be kept statically in /etc/passwd and /etc/group.

I don't know much about this. Sorry if it's an obtuse question. Any general
information would be appreciated.

Andrew


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: thousands of NTLM requests per day
  2017-02-28 15:17 thousands of NTLM requests per day Andrew Schulman
@ 2017-02-28 16:35 ` Andrey Repin
  2017-03-03 14:50   ` Andrew Schulman
  0 siblings, 1 reply; 3+ messages in thread
From: Andrey Repin @ 2017-02-28 16:35 UTC (permalink / raw)
  To: Andrew Schulman, cygwin

Greetings, Andrew Schulman!

> I got a call from our domain admins, asking me if I knew why my Windows 7
> host would be sending many thousands of NTLMv1 authentication requests per
> day. I don't know, and we're still trying to find out which application is
> doing that, but here's what I wonder:

> Could Cygwin be responsible for the authentication requests? I wonder about
> this because Cygwin now queries Windows for user and group information that
> used to be kept statically in /etc/passwd and /etc/group.

Do you use cygserver ? If not, try to set it up, it should help with domain
information caching. If the problem you observe is caused by Cygwin activity,
you should see a decrease in such requests.

> I don't know much about this. Sorry if it's an obtuse question. Any general
> information would be appreciated.


-- 
With best regards,
Andrey Repin
Tuesday, February 28, 2017 19:28:37

Sorry for my terrible english...


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: thousands of NTLM requests per day
  2017-02-28 16:35 ` Andrey Repin
@ 2017-03-03 14:50   ` Andrew Schulman
  0 siblings, 0 replies; 3+ messages in thread
From: Andrew Schulman @ 2017-03-03 14:50 UTC (permalink / raw)
  To: cygwin

> Greetings, Andrew Schulman!
> 
> > I got a call from our domain admins, asking me if I knew why my Windows 7
> > host would be sending many thousands of NTLMv1 authentication requests per
> > day. I don't know, and we're still trying to find out which application is
> > doing that, but here's what I wonder:
> 
> > Could Cygwin be responsible for the authentication requests? I wonder about
> > this because Cygwin now queries Windows for user and group information that
> > used to be kept statically in /etc/passwd and /etc/group.
> 
> Do you use cygserver ? If not, try to set it up, it should help with domain
> information caching. If the problem you observe is caused by Cygwin activity,
> you should see a decrease in such requests.

Thanks for the suggestion, Andrey. I'll keep it in mind for next time.

For the archive, this problem was unrelated to Cygwin. Jeffrey Altman answered
offline that "NTLM requests will be sent from the svchost.exe service when a
remote desktop connection is initiated." So I looked into the Nomachine NX
service that was running on my host, and found that it was responsible. I
disabled the service and the requests stopped.

So, not a Cygwin problem. Sorry for the noise, and thanks for the help.

Andrew


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2017-03-03 14:50 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-02-28 15:17 thousands of NTLM requests per day Andrew Schulman
2017-02-28 16:35 ` Andrey Repin
2017-03-03 14:50   ` Andrew Schulman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).