跳转到主内容

是否可以禁用基于 Kerberos 的通信的 RC4 加密?

Views:
157
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
nas
Last Updated:

适用于

  • ONTAP 9
  • 域控制器

回答

  • 在 9.12 及更高版本中,您可以禁用通告 RC4 加密类型
  • 在 9.11 及更低版本中,您无法为基于 Kerberos 的通信禁用 RC4 加密
    • 即使在 vserver 上启用了基于 Kerberos 的通信的 AES 加密,也不能禁用通告 RC4 加密类型
  • 当 AES 和 RC4 都启用时,vserver 将始终使用 AES
    • 除非客户端明确请求 RC4,否则将提供 AES 而不是 RC4
    • 如果有多个可用的加密类型,则由提供 Kerberos 票证的 DC 选择最强的加密类型
NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.