[38550] in Kerberos

home help back first fref pref prev next nref lref last post

MIT krb5 release 1.18 will remove single-DES support

daemon@ATHENA.MIT.EDU (Greg Hudson)
Tue May 28 15:09:45 2019

From: Greg Hudson <ghudson@mit.edu>
To: <kerberos-announce@mit.edu>
Date: Tue, 28 May 2019 15:01:41 -0400
Message-ID: <x7dpno2e73e.fsf@mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

This is advance notice that the MIT krb5 1.18 release, planned for near
the end of this year, will remove support for the single-DES encryption
types (chiefly des-cbc-crc) and their associated checksum types and salt
types.  Setting "allow_weak_crypto = true" will no longer re-enable
single-DES.

If your Kerberos environment still makes use of single-DES, please see
https://web.mit.edu/kerberos/krb5-latest/doc/admin/advanced/retiring-des.html
for documentation on how to transition to the AES encryption types.
_______________________________________________
kerberos-announce mailing list
kerberos-announce@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos-announce
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post