Hello Greg, Thank you for your reply. Since the procedure of a rollover of the master key seems to work fine I will stick to this solution. So actually I did not test the master_key_type solution now, but thanks anyway for mentioning the configuration option needed therefore.
Have a nice day Rainer Am 09.02.2017 um 06:18 schrieb Greg Hudson: > On 02/08/2017 07:33 AM, Rainer Krienke wrote: >>> If you configure "master_key_enctype = des3-cbc-sha1" in the [realms] >>> subsection for your realm in kdc.conf (or krb5.conf), I believe it >>> should work again (in both versions). Alternatively, you could rotate >>> the master key by following this procedure: >> >> This solution did not work for me. > > Many apologies; the actual variable name for this is "master_key_type". > -- Rainer Krienke, Uni Koblenz, Rechenzentrum, A22, Universitaetsstrasse 1 56070 Koblenz, Web: http://www.uni-koblenz.de/~krienke, Tel: +49261287 1312 PGP: http://www.uni-koblenz.de/~krienke/mypgp.html, Fax: +49261287 1001312
smime.p7s
Description: S/MIME Cryptographic Signature
________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos