In clientntlmv2auth.xml ----- If enabled, only an NTLMv2 and LMv2 response (both much more secure than earlier versions) will be sent. ---- "LMv2" should be LM? and "both" should be ... NTLMv2?
No, the documentation is correct. There is such thing as the LMv2 response, and indeed, it is a full, 128 bit encryped response on the password. It is 24 bytes long, and in the 'lm password' feild, for compatability.