Files
heimdal/kdc
Joseph Sutton 9a0372d992 kdc: Still prefer encryption types with "not default" salts except for des-cbc-crc
Samba clients are often machine accounts with non-default salts that
will fail if they can't use the AES encryption type they know the KDC
supports.  The problem is that arcfour-hmac-md5 has no salt so was
being used in preference.

Samba started to fail when

kdc_config->preauth_use_strongest_session_key = true;

was forced into the KDC configuration.

The history here is an attempt to avoid Kerberos v4 salts in des-cbc-crc
keys, but this instead broke Samba clients with AES-keys on machine accounts
as these have a non-default salt by default.  These accounts were incorrectly
restricted to arcfour-hmac-md5 and they didn't like that.

A broader fix than Samba commit 8e1efd8bd3bf698dc0b6ed2081919f49b1412b53

REF: https://lists.samba.org/archive/samba/2021-October/237844.html

Samba BUG: https://bugzilla.samba.org/show_bug.cgi?id=14864

Change-Id: Ia8908a5a2eef107e6b133d7f0e4343c1988c18bb
2022-01-17 15:42:03 -05:00
..
2011-07-24 13:07:07 -07:00
2022-01-14 17:59:49 -06:00
2022-01-03 16:17:01 +11:00
2022-01-14 17:59:49 -06:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2021-12-30 20:42:18 +11:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2021-12-30 20:42:18 +11:00
2022-01-15 18:54:57 +11:00
2022-01-14 17:59:49 -06:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2022-01-14 17:59:49 -06:00
2022-01-15 18:54:57 +11:00
2022-01-17 11:05:05 -06:00
2011-05-21 11:57:31 -07:00
2022-01-14 17:54:55 -06:00
2022-01-16 23:08:49 -06:00
2019-12-09 21:39:30 -06:00
2022-01-14 20:10:19 -06:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2022-01-15 18:54:57 +11:00
2011-05-21 11:57:31 -07:00
2022-01-14 17:59:49 -06:00
2019-12-04 21:34:44 -06:00