CVE-2016-2110: auth/ntlmssp: split allow_lm_response from allow_lm_key