supplementalCredentials with aes keys?

Stefan (metze) Metzmacher metze at samba.org
Sun Feb 18 19:40:56 GMT 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Love,

>> can you or someone else  with a windows ads server with support for AES
>> krb5 keys, send me the output of the following comments
> 
> I wont be able to do this for some time (on vacation).
ok, I'll wait for you or simo, to provide me this info...

Do you know which enctypes longhorn supports?

They same as the current heimdal?:
/* the 3 DES types must be first */
static const krb5_enctype all_etypes[] = {
    ETYPE_DES_CBC_MD5,
    ETYPE_DES_CBC_MD4,
    ETYPE_DES_CBC_CRC,
    ETYPE_AES256_CTS_HMAC_SHA1_96,
    ETYPE_ARCFOUR_HMAC_MD5,
    ETYPE_DES3_CBC_SHA1
};

Maybe you have a capture of a kinit against longhorn,
which contains the enctype salt mappings in the preauth-required reply...

metze
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org

iD8DBQFF2KvIm70gjA5TCD8RAiHaAJ99S63+7kG02++bocLpi8ezz15o/ACbBuHN
FN0gg2/ttCS/IdBWuWZUcc4=
=nLwr
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list