[OpenAFS] KRB5 Imported KA Keys and Win2K

Charles Clancy mgrtcc@cs.rose-hulman.edu
Tue, 1 May 2001 23:39:45 -0500 (EST)


>From the "ISSUES" file in the Kerberos 5 migration kit, it says that
Kerberos 5 supports the following key types:
  des-cbc-crc:normal
  des-cbc-crc:v4
  des-cbc-crc:afs3

When you use the migration tools to migrate accounts from the kaserver to
Kerberos, they are stored as type "des-cbc-crc:afs3".

Now, according to Microsoft's Win2K documentation, they support:
  DES-CBC-MD5
  DES-CBC-CRC

Does that mean they support all variations of des-cbc-crc?  I'm trying to
set up a trust relationship between a Win2K active directory tree and a
Kerberos 5 KDC which contains keys migrated from the kaserver.

Thanks!
_______________________________________________________
      Charles Clancy -- mgrtcc@cs.rose-hulman.edu
Senior UNIX Administrator, Rose-Hulman Computer Science