What should I do besides changing /etc/krb5.conf and /etc/kdc.conf so
that only 3DES tickets will be generated?

I have:

supported_enctypes = des3-hmac-sha1:normal
kdc_supported_enctypes = des3-hmac-sha1:normal

in the kdc.conf file, but I still have both types of tickets being
generated, DES and 3DES.

kadmin.local:  addprinc -randkey [EMAIL PROTECTED]
WARNING: no policy specified for [EMAIL PROTECTED]; 
defaulting to no policy
Principal "[EMAIL PROTECTED]" created.
kadmin.local:  ktadd ldap/pandora.distro.conectiva
Entry for principal ldap/pandora.distro.conectiva with kvno 3, encryption type Triple 
DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab.
Entry for principal ldap/pandora.distro.conectiva with kvno 3, encryption type DES cbc 
mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab.

Is it the "policy" thing?

Reply via email to