[31787] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Odd problem with Active Directory

daemon@ATHENA.MIT.EDU (Ravi Channavajhala)
Thu Dec 17 04:34:13 2009

MIME-Version: 1.0
In-Reply-To: <200912170948.53947.mc@suse.de>
Date: Thu, 17 Dec 2009 15:03:33 +0530
Message-ID: <73739dc10912170133q2e059cfeo260eb470d1bb1811@mail.gmail.com>
From: Ravi Channavajhala <ravi.channavajhala@dciera.com>
To: Michael Calmer <mc@suse.de>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit

On Thu, Dec 17, 2009 at 2:18 PM, Michael Calmer <mc@suse.de> wrote:

> One solution would be to tell the Windows Server, that your kerberos
> installation do not support aes.
>
> [libdefaults]
>    ...
>    default_tkt_enctypes = arcfour-hmac-md5 des-cbc-crc des-cbc-md5
>    default_tgs_enctypes = arcfour-hmac-md5 des-cbc-crc des-cbc-md5
>
> I hope this helps.

I remember a conversation from Samba group some time ago in which it
is possible to set the msDS-SupportedEncryptionTypes from the client.

>
> --
> MFG
>
>        Michael Calmer
-- 
Ravi Channavajhala
CTO
http://www.dciera.com

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


home help back first fref pref prev next nref lref last post