CVE-2022-37966 kdc: Assume trust objects support AES by default
authorJoseph Sutton <josephsutton@catalyst.net.nz>
Mon, 21 Nov 2022 22:32:34 +0000 (11:32 +1300)
committerStefan Metzmacher <metze@samba.org>
Tue, 13 Dec 2022 23:48:48 +0000 (00:48 +0100)
commita7e2f5d32e59758ca714e292e3aa0e51821a9d43
tree1ef5e68429815bb06db1c22546d7990f9204c861
parent1e32bfc0fdd5394268eb86f60de521722f783a50
CVE-2022-37966 kdc: Assume trust objects support AES by default

As part of matching the behaviour of Windows, assume that trust objects
support AES256, but not RC4, if not specified otherwise.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15219
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15237

Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz>
Reviewed-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
(cherry picked from commit 4bb50c868c8ed14372cb7d27e53cdaba265fc33d)

[jsutton@samba.org Added knownfail removals]
selftest/knownfail_heimdal_kdc
source4/kdc/db-glue.c