1.215 WN10-SO-000190

Information

Kerberos encryption types must be configured to prevent the use of DES and RC4 encryption suites.

GROUP ID: V-220936RULE ID: SV-220936r971535

Certain encryption types are no longer considered secure. This setting configures a minimum encryption type for Kerberos, preventing the use of the DES and RC4 encryption suites.

Solution

Configure the policy value for

Computer Configuration >> Windows Settings >> Security Settings >> Local Policies >> Security Options >> 'Network security: Configure encryption types allowed for Kerberos'

to 'Enabled' with only the following selected:

AES128_HMAC_SHA1AES256_HMAC_SHA1Future encryption types

See Also

https://workbench.cisecurity.org/benchmarks/23869

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-13

Plugin: Windows

Control ID: 8f84bf054d0e02ff85a949bd14d14fdea7bc3b63e9fd6fe8149c8543e3b9891b