In kdb_init_hist, just use the first key entry in the kadmin/history entry. This makes the history key work even if the enctype is disallowed by allow_weak_crypto=false or other configuration. https://github.com/krb5/krb5/commit/0414815956dacfb0976c8c51070b6b8adedc9597 Commit By: ghudson Revision: 23657 Changed Files: U trunk/src/lib/kadm5/srv/server_kdb.c