• Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • krb5
    • 2
    • rhel-sst-idm-ipa
    • ssg_idm
    • 2025-Q1-Bravo-S6, 2025-Q2-Bravo-S1
    • 5
    • False
    • Hide

      None

      Show
      None

      An change was mad upstream to disallow use of RC4 by default (an additional configuration parameter has to be set to allow it):
      https://github.com/krb5/krb5/commit/1b57a4d134bbd0e7c52d5885a92eccc815726463

      This restriction is also part of MS-KILE:
      https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-kile/6cfc7b50-11ed-4b4d-846d-6f08f0812919

      This change was reverted to avoid conflicts with the crypto-policy system. But it may still be needed for restricting use of RC4 for session keys specifically.

              jrische@redhat.com Julien Rische
              rhel-process-autobot RHEL Jira bot
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: