/usr/share/crypto-policies/policies/modules
NameSizeModeActions
AD-SUPPORT-LEGACY.pmod4690644editdlrm
AD-SUPPORT.pmod2830644editdlrm
ECDHE-ONLY.pmod1360644editdlrm
NO-ENFORCE-EMS.pmod2480644editdlrm
NO-SHA1.pmod1230644editdlrm
OSPP.pmod20720644editdlrm
PQ.pmod3850644editdlrm
SHA1.pmod1310644editdlrm
Edit: /usr/share/crypto-policies/policies/modules/AD-SUPPORT-LEGACY.pmod (469B)
# AD-SUPPORT-LEGACY subpolicy is intended to be used in Active Directory # environments where either accounts or trusted domain objects were not yet # migrated to AES or future encryption types. # This subpolicy enables all AES and RC4 Kerberos encryption types # to maximize Active Directory interoperability at the expense of security. cipher@kerberos = AES-256-CBC+ AES-128-CBC+ RC4-128+ mac@kerberos = HMAC-SHA2-384+ HMAC-SHA2-256+ HMAC-SHA1+ hash@kerberos = MD5+