Kerberos 5 Release 1.10.1
The MIT Kerberos Team announces the availability of the
krb5-1.10.1 release. The detached PGP
signature is available without going through the download
page, if you wish to verify the authenticity of a distribution
you have obtained elsewhere.
Please see the README file for a
more complete list of changes.
You may also see the current full
of fixed bugs tracked in our RT bugtracking system.
The Data Encryption Standard (DES) is widely recognized as
weak. The krb5-1.7 release contains measures to encourage sites
to migrate away from using single-DES cryptosystems. Among
these is a configuration variable that enables "weak" enctypes,
which now defaults to "false" beginning with krb5-1.8.
Major changes in 1.10.1
This is a bugfix release.
- Fix access controls for KDB string attributes
- Make the ASN.1 encoding of key version numbers interoperate
with Windows Read-Only Domain Controllers
- Avoid generating spurious password expiry warnings in cases
where the KDC sends an account expiry time without a password
Major changes in 1.10
- Code quality:
- Fix MITKRB5-SA-2011-006 and MITKRB5-SA-2011-007 KDC
denial of service vulnerabilities [CVE-2011-1527
CVE-2011-1528 CVE-2011-1529 CVE-2011-1530].
- Update the Fortuna implementation to more accurately
implement the description in Cryptography Engineering,
and make it the default PRNG.
- Add an alternative PRNG that relies on the OS native
- Developer experience:
- Add the ability for GSSAPI servers to use any keytab key
for a specified service, if the server specifies a
host-based name with no hostname component.
- In the build system, identify the source files needed for
per-message processing within a kernel and ensure that they remain
- Allow rd_safe and rd_priv to ignore the remote address.
- Rework KDC and kadmind networking code to use an event loop
- Add a plugin interface for providing configuration information.
- Administrator experience:
- Add more complete support for renaming principals.
- Add the profile variable ignore_acceptor_hostname in libdefaults. If
set, GSSAPI will ignore the hostname component of acceptor names
supplied by the server, allowing any keytab key matching the service
to be used.
- Add support for string attributes on principal entries.
- Allow password changes to work over NATs.
- End-user experience:
- Add the DIR credential cache type, which can hold a collection of
- Enhance kinit, klist, and kdestroy to support credential cache
collections if the cache type supports it.
- Add the kswitch command, which changes the selected default cache
within a collection.
- Add heuristic support for choosing client credentials based on the
- Add support for $HOME/.k5identity, which allows credential choice
based on configured rules.
- Add support for localization. (No translations are provided in this
release, but the infrastructure is present for redistributors to
- Protocol evolution:
- Make PKINIT work with FAST in the client library.
Known bugs reported against krb5-1.10.1 are listed
Please note that the HTML versions of these documents are
converted from texinfo, and that the conversion is imperfect.
If you want PDF, PostScript, or GNU info versions, please download
the documentation tarball.
You may retrieve the Kerberos 5 Release 1.10.1 source from
If you need to acquire the sources from some other distribution
site, you may verify them against the detached
PGP signature for krb5-1.10.1.
$Id: krb5-1.10.1.html,v 1.1 2012/03/08 21:21:13 tlyu Exp $
[ home ]
[ contact ]