Reorder DES algs to work around MIT pre-1.8 GSS
Pre-1.8 MIT GSS accept_sec_context() has a bug which treats des-cbc-md4 as if the received token format should be CFX. The previous DES alg ordering resulted in MIT KDCs issuing des-cbc-md4 session keys for service tickets which triggered this bug. Reorder the list so md4 is not preferred. Change-Id: I11269498a6eb8494044c618db29c43f62b0ced49
This commit is contained in:

committed by
Jeffrey Altman

parent
b45dd13c44
commit
7b1e954ad4
@@ -74,9 +74,9 @@ struct encryption_type *_krb5_etypes[] = {
|
||||
&_krb5_enctype_old_des3_cbc_sha1,
|
||||
#endif
|
||||
#ifdef HEIM_WEAK_CRYPTO
|
||||
&_krb5_enctype_des_cbc_crc,
|
||||
&_krb5_enctype_des_cbc_md4,
|
||||
&_krb5_enctype_des_cbc_md5,
|
||||
&_krb5_enctype_des_cbc_md4,
|
||||
&_krb5_enctype_des_cbc_crc,
|
||||
&_krb5_enctype_des_cbc_none,
|
||||
&_krb5_enctype_des_cfb64_none,
|
||||
&_krb5_enctype_des_pcbc_none,
|
||||
|
Reference in New Issue
Block a user