Oracle Solaris System Administration (MOSC)

MOSC Banner

Kerberos encryption types - compatibility question

edited Oct 24, 2011 4:50AM in Oracle Solaris System Administration (MOSC) 4 commentsAnswered ✓
Hello,
I've been assigned a task to debug/analyze problems related to configuring Solaris kerberos clients to AiX master KDCs and AiX/Linux slave KDCs.
I've gotten the impression this will be painful...

The context of my question is:
On the master kdc the krb.conf contains:
[realm]
...
supported_enctypes = des3-cbc-sha1:normal arcfour-hmac:normal aes256-cts:normal des-cbc-md5:normal des-cbc-crc:normal

On Solaris 8/11 (potential client) the kdc.conf(4) says:
...
aes256-cts-hmac-sha1-96:normal (see note below)
aes128-cts-hmac-sha1-96:normal
des3-cbc-sha1-kd:normal
arcfour-hmac-md5:normal
des-cbc-md5:normal


Note -
           The unbundled Strong Cryptographic  packages  must  be  <== by the way, which packages?

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center