[libdefaults]
-# default_cc_name = KCM:%{uid}
+# default_cc_type = KCM
+# default_cc_name = FILE:/tmp/krb5cc_%{uid}
ticket_lifetime = 24h
renew_lifetime = 24h
default_realm = MY.REALM
# default_keytab_name = FILE:/etc/krb5.keytab
-# default_etypes = des3-hmac-sha1 arcfour-hmac-md5
-# default_etypes_des = des3-hmac-sha1 des-cbc-crc des-cbc-md5 des-cbc-md4 arcfour-hmac-md5
+# default_etypes = des3-hmac-sha1 arcfour-hmac-md5 aes256-cts-hmac-sha1-96
+# default_etypes_des = des-cbc-crc des-cbc-md5 des-cbc-md4 des3-hmac-sha1 arcfour-hmac-md5 aes256-cts-hmac-sha1-96
kdc_timesync = 1
clockskew = 300
forwardable = true
# WARNING!!!
# As of heimdal 1.3 DES is deprecated, that means you MUST uncomment
# the following line if you use any flavor of kerberized NFS on
-# kernels prior to 2.6.35.
+# kernels prior to 2.6.35 and nfs-utils < 1.2.3.
# http://www.h5l.org/blog/index.php/2008/10/des-will-die-in-heimdal/
# allow_weak_crypto = true