support allow_weak_crypto in krb5.conf

XMLWordPrintable

    • Type: Enhancement
    • Resolution: Fixed
    • Priority: P4
    • 7
    • Affects Version/s: 7
    • Component/s: security-libs
    • None

      Latest MIT krb5 supports a allow_weak_crypto key in krb5.conf, when set to true, disallows DES be used in all kinds of etypes. We can support it also.

      Currently, MIT krb5's default value for this key is false, but it might become true one day.
      In MIT krb5 1.8, the default value becomes false. For compatibility reasons (which we always care most), we still choose true.

            Assignee:
            Weijun Wang
            Reporter:
            Weijun Wang
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: