[krbdev.mit.edu #1259]Re: Bug#169014: krb5-kdc no longer interops with Solaris SEAM

Sam Hartman via RT rt-comment at krbdev.mit.edu
Thu Nov 14 21:28:08 EST 2002


I b.believe you can work around this either by disabling
preauth_required on principals that need to log in from Solaris or
dropping des3-hmac-sha1 from supported_enctypes in your kdc.conf and
changing passwords.

Both of these work arounds have security implications unfortunately,
although not using des3 probably isn't that serious if you have a lot
of Solaris clients already.





More information about the krb5-bugs mailing list