We recently upgraded to OpenAFS 1.6.5 on our authen and file servers and also 
did a re-key for Kerberos V5.

The aklog command run on RHEL6 has the following error:

Kerberos error code returned by get_cred : -1765328184
aklog: Couldn't get asu.edu AFS tickets:
aklog: unknown RPC error (-1765328184) while getting AFS tickets 
allow_weak_enctypes may be required in the Kerberos configuration

As the error suggests, adding "allow_weak_crypto = true" to krb5.conf makes the 
errors go away.

Can someone tell me what the security ramifications of this are?

The Client AFS version is OpenAFS 1.6.1.

Thanks,

Greg Wilson

Reply via email to