Forum Discussion
JoaoFranca
Mar 14, 2026Tin Contributor
Kerberos and the End of RC4: Protocol Hardening and Preparing for CVE‑2026‑20833
CVE-2026-20833 addresses the continued use of the RC4‑HMAC algorithm within the Kerberos protocol in Active Directory environments. Although RC4 has been retained for many years for compatibility wit...
purandat
Aug 31, 2026Copper Contributor
Hello,
This is great post; however, I would like to know, if the available E type for Client, DC and Service account is AES and MSDS supportedEtype or DefaultDomainEtype is not configured, DCs are patched with June update.
What I understand is after April 2026, KDC operates with AES mode only, so by default it should use AES to encrypt the tickets.
However, we still see its encrypting using 0x27 which was default before April patch.
Any inputs on this will be appreciated.