Please handle AFS string2key with etype_info2

Sam Hartman hartmans at MIT.EDU
Wed May 21 15:46:01 EDT 2003


Hi.  I just discovered a bug in our KDC implementation of etype_info2
and it would be great if you didn't make the same mistake.

OUr client is going to be fairly strict about discarding all salt
hints besides etype_info2 if it sees etype_info2.  So it is important
for AFS salts to include s2kparams that indicate the salt is AFS.  We
are not currently doing that in our KDC, so our KDC will not be able
to use afs3 salt in krb5 with our client.  I will be fixing that
shortly.


More information about the krbdev mailing list