Anyone managed to build a static gssd?
Garrett Wollman
wollman at bimajority.org
Sun Jan 7 22:56:16 UTC 2018
<<On Sun, 7 Jan 2018 21:03:01 +0000, Rick Macklem <rmacklem at uoguelph.ca> said:
> Also, just fyi, RPCSEC_GSS Version 1 (the only one supported by FreeBSD)
> uses good old DES and uses the session key created by the Kerberos
> libraries via a TGT or keytab entry for this.
> --> As such, your TGT encryption choice must result in a 56/64 bit session key.
> (I never went beyond using DES for TGT encryption, but I suspect MIT
> doesn't like that idea;-)
That's good to know, and suggests that maybe I shouldn't bother with
trying this right now. As it happens, I've been working on
benchmarking recently, and the performance of NFSv4.1 is downright
terrible compared to v3, at least with my particular combination of
client and server. Haven't investigated yet where the slowdown is.
What would it take to get AES support?
-GAWollman
More information about the freebsd-fs
mailing list