linux-announce - Re: [[Linux-announce] ] arcfour keytab issues

linux-announce AT

Subject: Linux Mailing List

Re: [[Linux-announce] ] arcfour keytab issues

  • From: "Konrad Bucheli (PSI)" <konrad.bucheli AT>
  • To: linux-announce AT
  • Cc: Kohler Marco <marco.kohler AT>
  • Subject: Re: [[Linux-announce] ] arcfour keytab issues
  • Date: Thu, 30 Nov 2023 13:57:00 +0100
PS: mit RHEL9 werden wir kein arcfour-hmac mehr anbieten

On 30.11.23 13:53, Konrad Bucheli (PSI) wrote:

With Release 8.9 of RedHat Enterprise Linux arcfour-hmac was removed from the legacy crypto algorithm set of Kerberos. As this is still used in some keytabs I brought it back today with an emergency release of our Puppet code.

Nonetheless please check your keytabs for the cryto algorithms used:

# klist -e -d -K -k /path/to/example.keytab
Keytab name: FILE:/path/to/example.keytab
KVNO Principal
---- --------------------------------------------------------------------------
   5 gac-example AT D.PSI.CH (DEPRECATED:arcfour-hmac) (0xb1223971f9cf567d71680b9b366b3126)

and if it is just arcfour-hmac please consider scheduling a replacement. To do so please contact the AD-Team (Marco Kohler).

Please check the date on the security advisory by Microsoft suggesting to disable RC4:

Kind regards

Paul Scherrer Institut
Konrad Bucheli
Linux Systems Engineer
Core Linux Research Services
Science IT Infrastructure and Services department (AWI)
Forschungstrasse 111
5232 Villigen PSI

Phone: +41 56 310 27 24
konrad.bucheli AT

