On 06/07/2011 07:01 PM, Luk Claes wrote:
> On 06/06/2011 05:37 PM, Alberto Gonzalez Iniesta wrote:
>> Adding the following line in the [libdefaults] section of /etc/krb5.conf
>> fixed the problem for me (tm), probably not the best solution, but
>> works:
>> permitted_enctypes = des-cbc-md5
> 
> It's probably better to set enable_weak_crypto=yes, does that work?

'allow_weak_crypto = true', that is.

>> I also exported ONLY the DES-CBC-MD5:NORMAL key for my sid host:
>> kadmin.local: ktadd -k lib.keytab -e DES-CBC-MD5:NORMAL  host/lib
>> (probably not needed, but just to stay on the ""safe"" side)

Cheers

Luk



-- 
To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/4dee5af0.3040...@debian.org

Reply via email to