[32171] in Kerberos
Re: Win 2008R2 kdc and linux client: no support for encryption
daemon@ATHENA.MIT.EDU (Christopher D. Clausen)
Tue Mar 23 11:32:48 2010
Message-ID: <1ADD5D4AD87F4D45B404E3CCBFC16D39@CDCHOME>
From: "Christopher D. Clausen" <cclausen@acm.org>
To: "Michael B Allen" <ioplex@gmail.com>
Date: Tue, 23 Mar 2010 10:32:05 -0500
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
John Jasen <jjasen@realityfailure.org> wrote:
> Michael B Allen wrote:
>
>> Actually I would not be surprised if that "hot fix" is never made
>> public. DES is being phased out. If you have any Windows accounts that
>> use DES, you should update them to AES-256, AES-128 or RC4 in that
>> order of preference.
>
> I'd have to check again, but I think linux-nfs still uses DES.
OpenAFS also requires single DES, which is what what the original poster is
using based on a similar message sent to the openafs mailing list.
<<CDC
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos