Debian Developers - Re: Heimdal and openssh

This is Interesting: Free IT Magazines  
Home > Archive > Debian Developers > January 2006 > Re: Heimdal and openssh





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author Re: Heimdal and openssh
Russ Allbery

2006-01-09, 11:02 pm

Juha J=E4ykk=E4 <juhaj@iki.fi> writes:

[vbcol=seagreen]
> Perhaps this is THE patch which makes them all work together while
> openssh folks claim they don't? This is a side-issue, but it would be
> nice to know.


That may very well be the case, yeah. I've not done a lot of
experimentation.

> Ahem... my krb5.conf says "permitted_enctypes =3D aes256-cts-hmac-sha1-96"
> (in libdefaults). So this is the culprit here? [Please, do not patronize
> me on using a non-recommended config. =3D) It's simply that I think DES
> has no security to speak of these days. 3DES might be worth trying,
> though.]


In further discussion, this turned out to be the problem that started all
the attempts at rebuilding things (in case anyone else happens upon this
thread). The versions of everything in sarge aren't set up to support
256-bit AES as the only supported enctype, but this will probably work in
etch.

--=20
Russ Allbery (rra@debian.org) <http://www.eyrie.org/~eagle/>
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com