Re: supported_enctypes question

2009-08-27 Thread Tom Yu
Kevin Coffman k...@citi.umich.edu writes: Wed, Aug 26, 2009 at 3:21 PM, Tom Yut...@mit.edu wrote: Russ Allbery r...@stanford.edu writes: default_enctypes, maybe? Possibly... though we do already have default_tkt_enctypes and default_tgs_enctypes, which mean something completely different.

Re: supported_enctypes question

2009-08-27 Thread Kevin Coffman
On Thu, Aug 27, 2009 at 3:23 PM, Tom Yut...@mit.edu wrote: Kevin Coffman k...@citi.umich.edu writes:  Wed, Aug 26, 2009 at 3:21 PM, Tom Yut...@mit.edu wrote: Russ Allbery r...@stanford.edu writes: default_enctypes, maybe? Possibly... though we do already have default_tkt_enctypes and

supported_enctypes question

2009-08-26 Thread John Harris
Greetings, I currently have a MIT KDC where I need to use the des-cbc-crc:normal encryption type on *one* service principal. The rest of my KDC all principals can be aes or rc4. I'm confused as to what I need in my config and what will work. If I just have aes256-cts:normal and

Re: supported_enctypes question

2009-08-26 Thread Tom Yu
John Harris har...@ucdavis.edu writes: Greetings, I currently have a MIT KDC where I need to use the des-cbc-crc:normal encryption type on *one* service principal. The rest of my KDC all principals can be aes or rc4. I'm confused as to what I need in my config and what will work. If

Re: supported_enctypes question

2009-08-26 Thread Tom Yu
Russ Allbery r...@stanford.edu writes: Tom Yu t...@mit.edu writes: John Harris har...@ucdavis.edu writes: If I just have aes256-cts:normal and rc4-hmac:normal listed in kdc.conf in the supported_enctypes field, I'm still able to create the des-cbc-crc:normal service principal I need. In

Re: supported_enctypes question

2009-08-26 Thread Russ Allbery
Tom Yu t...@mit.edu writes: John Harris har...@ucdavis.edu writes: If I just have aes256-cts:normal and rc4-hmac:normal listed in kdc.conf in the supported_enctypes field, I'm still able to create the des-cbc-crc:normal service principal I need. In fact, I can kinit -S for it and obtain

Re: supported_enctypes question

2009-08-26 Thread Kevin Coffman
Wed, Aug 26, 2009 at 3:21 PM, Tom Yut...@mit.edu wrote: Russ Allbery r...@stanford.edu writes: Tom Yu t...@mit.edu writes: John Harris har...@ucdavis.edu writes: If I just have aes256-cts:normal and rc4-hmac:normal listed in kdc.conf in the supported_enctypes field, I'm still able to

Re: supported_enctypes question

2009-08-26 Thread John Harris
Thanks so much Tom; that makes sense to me. I would vote for not changing it since it's been like, you know, 20 years in the making, but if we're gonna change it perhaps: harris_enctypes ? :) Tom Yu wrote: John Harris har...@ucdavis.edu writes: Greetings, I currently have a MIT KDC