Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
This would improve Kdiag tool allowing it to dump relevant information and tell if AES 256 is enabled or not on the host. If not, prompt users to install the JCE Policy File according to JCE Unlimited Strength Jurisdiction Policy File. This is important because a common issue when deploying Kerberos is, AES-256 encryption type is configure and used in krb5.conf, but in JRE AES-256 isn't enabled by default in a typical Oracle Java installation.
Attachments
Issue Links
- is related to
-
SLIDER-1035 Kdiag enhancements
- Resolved