Kerberos 5 Release 1.8

Kerberos 5 Release 1.8 is now available

The MIT Kerberos Team announces the availability of the krb5-1.8 release. The detached PGP signature is available without going through the download page, if you wish to verify the authenticity of a distribution you have obtained elsewhere.

Please see the README file for a more complete list of changes.

You may also see the current full list of fixed bugs tracked in our RT bugtracking system.

DES transition

The krb5-1.8 release disables single-DES cryptosystems by default. As a result, you may need to add the libdefaults setting "allow_weak_crypto = true" to communicate with existing Kerberos infrastructures if they do not support stronger ciphers.

The Data Encryption Standard (DES) is widely recognized as weak. The krb5-1.7 release contains measures to encourage sites to migrate away from using single-DES cryptosystems. Among these is a configuration variable that enables "weak" enctypes, which now defaults to "false" beginning with krb5-1.8. The krb5-1.8 release includes additional measures to ease the transition away from single-DES. These additional measures include:

Major changes in 1.8

The krb5-1.8 release contains a large number of changes, featuring improvements in the following broad areas:

Code quality:

Developer experience

End-user experience:

Administrator experience:

Protocol evolution:

Known Bugs

Known bugs reported against krb5-1.8 are listed here.

Documentation for krb5-1.8

Please note that the HTML versions of these documents are converted from texinfo, and that the conversion is imperfect. If you want PostScript or GNU info versions, please download the documentation tarball.

Retrieving Kerberos 5 Release 1.8

You may retrieve the Kerberos 5 Release 1.8 source from here. If you need to acquire the sources from some other distribution site, you may verify them against the detached PGP signature for krb5-1.8.

$Id: krb5-1.8.html,v 1.3 2010/03/30 19:05:45 tlyu Exp $
MIT Kerberos [ home ] [ contact ]