[krbdev.mit.edu #7903] Remove des3 and arcfour from supported_enctypes
Tom Yu via RT
rt-comment at krbdev.mit.edu
Tue Apr 15 14:33:28 EDT 2014
The des3 and arcfour enctypes use weaker string-to-key algorithms than the AES enctypes.
Remove them from the default supported_enctypes setting to avoid generating password-
derived keys for them. This could cause compatibility problems with Windows XP and similar
vintage Windows platforms, but XP was recently completely desupported. We should document
these compatibility considerations with this change.
More information about the krb5-bugs
mailing list