[krbdev.mit.edu #7903] Remove des3 and arcfour from supported_enctypes

Tom Yu via RT rt-comment at krbdev.mit.edu
Tue Apr 15 14:33:28 EDT 2014


The des3 and arcfour enctypes use weaker string-to-key algorithms than the AES enctypes.  
Remove them from the default supported_enctypes setting to avoid generating password-
derived keys for them.  This could cause compatibility problems with Windows XP and similar 
vintage Windows platforms, but XP was recently completely desupported.  We should document 
these compatibility considerations with this change.


More information about the krb5-bugs mailing list