What should I do besides changing /etc/krb5.conf and /etc/kdc.conf so that only 3DES tickets will be generated?
I have: supported_enctypes = des3-hmac-sha1:normal kdc_supported_enctypes = des3-hmac-sha1:normal in the kdc.conf file, but I still have both types of tickets being generated, DES and 3DES. kadmin.local: addprinc -randkey [EMAIL PROTECTED] WARNING: no policy specified for [EMAIL PROTECTED]; defaulting to no policy Principal "[EMAIL PROTECTED]" created. kadmin.local: ktadd ldap/pandora.distro.conectiva Entry for principal ldap/pandora.distro.conectiva with kvno 3, encryption type Triple DES cbc mode with HMAC/sha1 added to keytab WRFILE:/etc/krb5.keytab. Entry for principal ldap/pandora.distro.conectiva with kvno 3, encryption type DES cbc mode with CRC-32 added to keytab WRFILE:/etc/krb5.keytab. Is it the "policy" thing?
