In kdb_init_hist, just use the first key entry in the kadmin/history entry. This makes the history key work even if the enctype is disallowed by allow_weak_crypto=false or other configuration. http://src.mit.edu/fisheye/changelog/krb5/?cs=23657 Commit By: ghudson Revision: 23657 Changed Files: U trunk/src/lib/kadm5/srv/server_kdb.c