key salting and kerberos v5

Calimer0 cryos98 at yahoo.com
Sun Apr 27 19:39:00 EDT 2003


from kerberos FAQ 2.0:

> In Kerberos 5 the complete principal name (including the realm) is used as the salt

but listing principals properties with kadmin what I see is:

[...]
Key: vno 1, triple DES cbc mode with HMAC/sha1, no salt
Key: vno 1, DES cbc mode with CRC-32, no salt
[...]

I thought that key salting was the default behaviour, now:
- I was wrong, key salting is not active by default and must be someway turned on 
- I turned off key salting (please explain me how I did it..! :)
- ??

I have installed MIT kerberos v 1.2.6
can anybody help?
thanks in advance

mark


More information about the Kerberos mailing list