Skip to content

Commit d8e5093

Browse files
Merge pull request #10603 from WAftring/patch-1
Update Kerberos protocol registry settings and notes
2 parents 609d145 + be3149e commit d8e5093

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

support/windows-server/windows-security/kerberos-protocol-registry-kdc-configuration-keys.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -285,3 +285,6 @@ The registry entries that are listed in this section must be added to the follow
285285
This value sets AES as the default encryption type for session keys on accounts that aren't marked with a default encryption type.
286286

287287
For more information, see [KB5021131: How to manage the Kerberos protocol changes related to CVE-2022-37966](https://support.microsoft.com/topic/kb5021131-how-to-manage-the-kerberos-protocol-changes-related-to-cve-2022-37966-fd837ac3-cdec-4e76-a6ec-86e67501407d).
288+
289+
> [!IMPORTANT]
290+
> After applying the April 2026 Windows updates the default value will be changed to 0x18 (AES-SHA1). For additional information see [How to manage Kerberos KDC usage of RC4 for service account ticket issuance changes related to CVE-2026-20833](https://support.microsoft.com/topic/how-to-manage-kerberos-kdc-usage-of-rc4-for-service-account-ticket-issuance-changes-related-to-cve-2026-20833-1ebcda33-720a-4da8-93c1-b0496e1910dc)

0 commit comments

Comments
 (0)