Finally getting back to you.

The Bad news: You are of course right, but I have ~40 old build machines to 
support and alas am not able to walk
away from them.

The Good News: FreeIPA and the NIS-plugin works with these (FreeBSD 3.51)
               My initial test client had issues and I moved on to another test 
client and it works!

Next I need to figure out how to server AMD and autofs maps with the nis-plugin

Thanks for your help.

Simo Sorce wrote:
On Tue, 2009-10-06 at 14:43 -0700, garyv wrote:
So my client needs to understand SSHA encryption?
Did I understand that correct?

I have some really old clients that will only do DES.
(don't laugh)

Is there a way to change how which encryption algorithm it uses?

No and exposing passwords over the network is a particularly bad idea
anyways. Can't you use a pam module on your client to perform kerberos
authentication instead of compromising all your network accounts for a
stupid client ?


