[22450] in Kerberos

home help back first fref pref prev next nref lref last post

UNIX GSS-API / Windows SSPI :

daemon@ATHENA.MIT.EDU (Jacques Lebastard)
Tue Sep 14 12:50:47 2004

Message-ID: <414720FE.2030601@evidian.com>
Date: Tue, 14 Sep 2004 18:49:02 +0200
From: Jacques Lebastard <jacques.lebastard@evidian.com>
MIME-Version: 1.0
To: kerberos@mit.edu
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit
Errors-To: kerberos-bounces@mit.edu


Hi there,

our client/server application uses either SSPI (Windows) or GSS-API 
(UNIX) in order to establish a secure context.

In order to make it work properly, I had to set specific encryption 
types in the krb5.conf file of the UNIX server:

[libdefaults]
         default_tkt_enctypes = des-cbc-md5
         default_tgs_enctypes = des-cbc-md5

Does that mean that the established session keys are DES 64 bits *ONLY* 
? It sounds like a weak encryption...

Are any other encryption types compatible between MIT and Windows 
2000/2003 (native) Kerberos implementations ?

-- 
Mr. Jacques LEBASTARD            mailto:jacques.lebastard@evidian.com
EVIDIAN S.A.                     www.evidian.com
Rue Jean Jaurès                  Tel: +33 1 30 80 77 86
F-78340 LES CLAYES SOUS BOIS     Fax: +33 1 30 80 77 99



________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post