There is a Group Policy option in the security options that sets the Allowed encryption types.
>From a Windows 7 or Windows Server 2008 R2 machine: Create a group policy object on OU=Domain Controllers or use an existing policy Set the policy option "Network security: Configure encryption types allowed for Kerberos" Select which enctypes to allow -Ross -----Original Message----- From: kerberos-boun...@mit.edu [mailto:kerberos-boun...@mit.edu] On Behalf Of Lars Schimmer Sent: Thursday, March 04, 2010 7:39 AM To: openafs-i...@openafs.org; kerberos@mit.edu >> kerberos Subject: Win 2008R2 DES eanble? -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi! Sorry for a bit OT question: I want to extend our AD with a Windows 2008R2 server with KDC enabled. Now I know I need to enable DES enctype again to be able to use OpenAFS with such a KDC, but I am a bit lost where to enable this. Found a few point on google so far: - -administrative tools for server - -for each client seperate of the AD But what is the real solution? MfG, Lars Schimmer - -- - ------------------------------------------------------------- TU Graz, Institut für ComputerGraphik & WissensVisualisierung Tel: +43 316 873-5405 E-Mail: l.schim...@cgv.tugraz.at Fax: +43 316 873-5402 PGP-Key-ID: 0x4A9B1723 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAkuP1A0ACgkQmWhuE0qbFyNjAQCgi473Qem43r/cOepipBI0MNvR DDEAn0Y8YmWl0UnGMQfFrwxoQTPNmY+W =j10e -----END PGP SIGNATURE----- ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos