Auto-detecting broken arcfour-hmac code

Love lha at stacken.kth.se
Tue Sep 2 14:08:59 GMT 2003


Jim McDonough <jmcd at us.ibm.com> writes:

> Anyone have any ideas about detecting whether the arcfour-hmac code is
> broken, as before last week or so when the fix was put in the snapshot?
> Samba needs to know and not use it if it's broken, but I'd like to use it
> when possible and not just generally disable it.  THere are a lot of 0.4e
> installs out there...

I would guess that everything older then yet-to-be-released 0.7 is broken.

If you can find a enum KEYTYPE_ARCFOUR_56 in krb5.h, heimdal is probably ok.

I've been thinking about adding a version number to krb5.h

Love

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 477 bytes
Desc: not available
Url : http://lists.samba.org/archive/samba-technical/attachments/20030902/e7832905/attachment.bin


More information about the samba-technical mailing list