freeipa/install/updates/50-krbenctypes.update
Christian Heimes bc56642bf9 Block camellia in krbenctypes update in FIPS
Add FIPS conditional to updates to prevent updater from adding camellia
encsalttypes.

Fixes: https://pagure.io/freeipa/issue/8111
Signed-off-by: Christian Heimes <cheimes@redhat.com>
Reviewed-By: Rob Crittenden <rcritten@redhat.com>
2019-11-05 11:48:28 -05:00

10 lines
502 B
Plaintext

dn: cn=$REALM,cn=kerberos,$SUFFIX
${FIPS}add: krbSupportedEncSaltTypes: camellia128-cts-cmac:normal
${FIPS}add: krbSupportedEncSaltTypes: camellia128-cts-cmac:special
${FIPS}add: krbSupportedEncSaltTypes: camellia256-cts-cmac:normal
${FIPS}add: krbSupportedEncSaltTypes: camellia256-cts-cmac:special
add: krbSupportedEncSaltTypes: aes128-sha2:normal
add: krbSupportedEncSaltTypes: aes128-sha2:special
add: krbSupportedEncSaltTypes: aes256-sha2:normal
add: krbSupportedEncSaltTypes: aes256-sha2:special