On Mon, 18 Jan 2010, at 12:53 -0800, Russ Allbery wrote:

Adding the line
allow_weak_enctypes = yes
to the [libdefaults] section (is this the right syntax/place?)
unfortunately does not help.

Because it's "allow_weak_crypto", not "allow_weak_enctypes".  Otherwise,
yes, that's the problem and that should fix it.

Thank you very much, this really helped.

By the way, what are the best practices to avoid "weak crypto"? Do you (not only in Stanford) have all the krb5/afs keys in DES3, AES, ...?

Jan

--
Jan Pospisil, Ph.D.           e-mail: [email protected]
University of West Bohemia    phone:  (+420) 37763-2675
Department of Mathematics     fax:    (+420) 37763-2602
Plzen, Czech Republic         address: Univerzitni 22, 306 14

_______________________________________________
OpenAFS-info mailing list
[email protected]
https://lists.openafs.org/mailman/listinfo/openafs-info

Reply via email to