2.3.11.4 Ensure 'Network Security: Encryption types allowed for Kerberos' is set to 'AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future'

Information

This policy setting allows you to set the encryption types that Kerberos is allowed to use.

Solution

Ensure 'Network Security: Configure encryption types allowed for Kerberos' is set to 'AES128_HMAC_SHA1, AES256_HMAC_SHA1, Future encryption types'

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13, CSCv6|16.14

Plugin: Windows

Control ID: e9f11a73aa5a8a44e9b1df8248df227337209c9df9c0e0ab994e8304759c6ba5