Bug 1658941

Summary: Add a note about deprecation of DES in RHEL7
Product: Red Hat Enterprise Linux 7 Reporter: Thorsten Scherf <tscherf>
Component: doc-Security_GuideAssignee: Mirek Jahoda <mjahoda>
Status: CLOSED CURRENTRELEASE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: unspecified Docs Contact:
Priority: medium    
Version: 7.7CC: rharwood, rhel-docs
Target Milestone: rcKeywords: Documentation
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-07-16 12:30:14 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Thorsten Scherf 2018-12-13 08:39:41 UTC
Document URL: 
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-securing_services#sec-Securing_NFS

Section Number and Name: 
4.3.7. Securing NFS

Describe the issue: 
In RHEL7 we no longer support DES for Kerberos principal keys. We should add a note to the NFS section to make the deprecation visible for customers setting up secure NFS. 

Suggestions for improvement: 
"""
The version of krb5-libs shipped in Red Hat Enterprise Linux 7 does not support the usage of DES encryption keys in new deployments. There always have been compatibility issues with Microsoft Active Directory and this resurfaced again with the introduction of FAST into Kerberos’s protocol. DES is deprecated and has been left into the product only as a compatibility option (it is disabled by default in fact).
"""


Additional information:

Comment 6 Mirek Jahoda 2019-07-16 12:30:14 UTC
The update has been published on the Customer Portal:
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-securing_services#sec-Securing_NFS