Hello Greg,

Thank you for your reply. Since the procedure of a rollover of the
master key seems to work fine I will stick to this solution. So actually
I did not test the master_key_type solution now, but thanks anyway for
mentioning the configuration option needed therefore.

Have a nice day
Rainer

Am 09.02.2017 um 06:18 schrieb Greg Hudson:
> On 02/08/2017 07:33 AM, Rainer Krienke wrote:
>>> If you configure "master_key_enctype = des3-cbc-sha1" in the [realms]
>>> subsection for your realm in kdc.conf (or krb5.conf), I believe it
>>> should work again (in both versions).  Alternatively, you could rotate
>>> the master key by following this procedure:
>>
>> This solution did not work for me.
> 
> Many apologies; the actual variable name for this is "master_key_type".
> 


-- 
Rainer Krienke, Uni Koblenz, Rechenzentrum, A22, Universitaetsstrasse  1
56070 Koblenz, Web: http://www.uni-koblenz.de/~krienke, Tel: +49261287 1312
PGP: http://www.uni-koblenz.de/~krienke/mypgp.html,     Fax: +49261287
1001312

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to