we have updated our samba AD domain from 4.4.x to 4.5.x.

The release notes for 4.5.0 included  "NTLMv1 authentication disabled by default".

So we had to enable it to get our radius (freeradius) server working (for 802.1x).

What would be the best way to change the freeradius configuration in such a way,

that we can disable NTLMv1 again.

The radius server is used for WLAN (802.1x) and for VPN.

How insecure is NTLMv1 ?


