We're in the process of rolling our mkey to get off 3des, and we found[...]
that someone in the before-times has put this line in our kdc.conf:
master_key_type = des3-hmac-sha1
Would things break if I just took this line out? Or would the kdc fail to start because a K/M of the default enctype isn't present yet?used when the mkey is entered from the keyboard (including during KDB creation). Assuming you are using a stash file, you should be able to
From a review of the code, I am pretty sure that this setting is only
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 296 |
Nodes: | 16 (2 / 14) |
Uptime: | 83:04:34 |
Calls: | 6,658 |
Calls today: | 4 |
Files: | 12,203 |
Messages: | 5,333,520 |
Posted today: | 1 |