We're in the process of rolling our mkey to get off 3des, and we found[...]
that someone in the before-times has put this line in our kdc.conf:
master_key_type = des3-hmac-sha1
Would things break if I just took this line out? Or would the kdc fail to start because a K/M of the default enctype isn't present yet?used when the mkey is entered from the keyboard (including during KDB creation). Assuming you are using a stash file, you should be able to
From a review of the code, I am pretty sure that this setting is only
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 113 |
Nodes: | 8 (1 / 7) |
Uptime: | 134:05:42 |
Calls: | 2,501 |
Files: | 8,696 |
Messages: | 1,925,782 |