Am 07.11.2014 um 14:46 schrieb Brandon Allbery:
> On Fri, 2014-11-07 at 11:41 +0100, Andreas Ladanyi wrote:
>> Kerberos error code returned by get_cred : -1765328370
> KRB5KDC_ERR_ETYPE_NOSUPP
>
> You are probably still using DES, and need "allow_weak_crypto = true" in
> [libdefaults] on clients and the KDC. An answer for the future (and
> possibly necessary as some Kerberos implementations are disabling DES
> entirely) is to migrate the AFS cell to rxkad-k5.
>
allow_weak_crypto = true is set in the krb5.conf on test client pc. It
doesnt work.

The afs/"AFS_CELL" service principal on the new server with FreeIPA is:

afs/"AFS_CELL"@Realm B (des-cbc-crc), no salt

Is this the correct key type ? I think it is.




Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to