Hi Folks,

I'm nominally aware that the ability for adcli joins to honor custom enctypes 
became a thing around 2018, but I'm having a heck of a time finding guidance 
online for setting permitted enctypes so that keytabs don't create keys for DES 
and RC4.

Our environment uses a mixture of SSSD 2.2.3, and 2.6.3, joining to MS Active 
Directory, which my Windows admins have said run MS Server 2019 with Active 
Directory 2016.

I've been digging around on search engines and picking through various krb5 
docs, and I think SSSD will refer to krb5.conf, and might be reading 
supported_enctypes or permitted_enctypes, but I'm not sure how to put it all 
together.

Thanks very much!
- Kodiak Firesmith

Sent with [Proton Mail](https://proton.me/) secure email.
_______________________________________________
sssd-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to