+Mon May 20 17:25:09 1996 Theodore Y. Ts'o <tytso@mit.edu>
+
+ * krb5.conf.M: Document kdc_req_checksumtype,
+ as_req_checksum_type, and safe_checksum_type.
+
+ * krb5.conf: Remove the tkt_lifetime parameter altogether. We may
+ end up doing it slightly differently post-Beta 6...
+
Mon May 13 20:39:33 1996 Theodore Y. Ts'o <tytso@mit.edu>
* krb5.conf: Change the default ticket lifetime to something
KDC and in order to correct for an inaccurate system clock. This
corrective factor is only used by the Kerberos library.
-.IP checksum_type
+.IP kdc_req_checksum_type
For compatability with DCE security servers which do not support
the default CKSUMTYPE_RSA_MD5 used by this version of Kerberos. Use
a value of 2 to use the CKSUMTYPE_RSA_MD4 instead. This applies to
DCE 1.1 and earlier.
+.IP ap_req_checksum_type
+This allows you to set the checksum type used in the authenticator of
+KRB_AP_REQ messages. The default value for this type is CKSUMTYPE_RSA_MD5.
+For compatibility with applications linked against DCE Kerberos libraries,
+use a value of 2 to use the CKSUMTYPE_RSA_MD4 instead. This applies to
+DCE 1.1 and earlier.
+
+.IP safe_checksum_type
+This allows you to set the keyed-checksum type used in
+KRB_SAFE messages. The default value for this type is CKSUMTYPE_RSA_MD5_DES.
+For compatibility with applications linked against DCE Kerberos libraries,
+use a value of 3 to use the CKSUMTYPE_RSA_MD4_DES instead. This applies to
+DCE 1.1 and earlier.
+
.IP ccache_type
User this parameter on systems which are DCE clients, to specify the
type of cache to be created by kinit, or when forwarded tickets are