krb5-1.8.1-beta2 is available

Tom Yu tlyu at MIT.EDU
Wed Mar 31 18:34:12 EDT 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[There was no announcement of krb5-1.8.1-beta1 due to some last-minute
bugfixes.]

MIT krb5-1.8.1-beta2 is now available for download from

         http://web.mit.edu/kerberos/dist/testing.html

The main MIT Kerberos web page is

         http://web.mit.edu/kerberos/

This is the code freeze for the krb5-1.8.1 release, which will
probably have a final release early next week.

The README file contains a more extensive list of changes.

The Data Encryption Standard (DES) is widely recognized as weak.  The
krb5-1.7 release contains measures to encourage sites to migrate away
- From using single-DES cryptosystems.  Among these is a configuration
variable that enables "weak" enctypes, which now defaults to "false"
beginning with krb5-1.8.  The krb5-1.8 release includes additional
measures to ease the transition away from single-DES.  These
additional measures include:

* enctype config enhancements (so you can do "DEFAULT +des", etc.)
* new API to allow applications (e.g. AFS) to explicitly reenable weak
  crypto
* easier kadmin history key changes

Major changes in 1.8.1
- ----------------------

This is primarily a bugfix release.

* MITKRB5-SA-2010-002 CVE-2010-0628 denial of service in SPNEGO

* Support IPv6 in kpasswd client.

* Fix an authorization data type number assignment that conflicted
  with an undocumented Microsoft usage.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (SunOS)

iEYEARECAAYFAkuzze4ACgkQSO8fWy4vZo6m9QCghCNFwEs4H7G1uksdtpfoKGCY
TOoAoM0C1MhOQG+13RrNp06IC2cGybTo
=sETP
-----END PGP SIGNATURE-----




More information about the krbdev mailing list