[Freeipa-devel] [PATCH] 0114 ipa-sam: fix setting encryption type for trust object already created

Simo Sorce simo at redhat.com
Sat Sep 7 14:47:27 UTC 2013


On Thu, 2013-09-05 at 17:44 +0300, Alexander Bokovoy wrote:
> +       enctypes = KERB_ENCTYPE_DES_CBC_CRC |
> +                  KERB_ENCTYPE_DES_CBC_MD5 |
> +                  KERB_ENCTYPE_RC4_HMAC_MD5 |
> +                  KERB_ENCTYPE_AES128_CTS_HMAC_SHA1_96 |
> +                  KERB_ENCTYPE_AES256_CTS_HMAC_SHA1_96; 

Why are we hardcoding support for *DES* enctype, we disable DES by
default and also Windows never uses it by default.

Simo.

-- 
Simo Sorce * Red Hat, Inc * New York




More information about the Freeipa-devel mailing list