Problem with db master password migrating kerberos server to new machine
Rainer Krienke
krienke at uni-koblenz.de
Thu Feb 9 12:02:51 EST 2017
Hello Greg,
Thank you for your reply. Since the procedure of a rollover of the
master key seems to work fine I will stick to this solution. So actually
I did not test the master_key_type solution now, but thanks anyway for
mentioning the configuration option needed therefore.
Have a nice day
Rainer
Am 09.02.2017 um 06:18 schrieb Greg Hudson:
> On 02/08/2017 07:33 AM, Rainer Krienke wrote:
>>> If you configure "master_key_enctype = des3-cbc-sha1" in the [realms]
>>> subsection for your realm in kdc.conf (or krb5.conf), I believe it
>>> should work again (in both versions). Alternatively, you could rotate
>>> the master key by following this procedure:
>>
>> This solution did not work for me.
>
> Many apologies; the actual variable name for this is "master_key_type".
>
--
Rainer Krienke, Uni Koblenz, Rechenzentrum, A22, Universitaetsstrasse 1
56070 Koblenz, Web: http://www.uni-koblenz.de/~krienke, Tel: +49261287 1312
PGP: http://www.uni-koblenz.de/~krienke/mypgp.html, Fax: +49261287
1001312
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5085 bytes
Desc: S/MIME Cryptographic Signature
Url : http://mailman.mit.edu/pipermail/kerberos/attachments/20170209/8d469be0/attachment.bin
More information about the Kerberos
mailing list