Can RC4 encryption for Kerberos-based communication be disabled?
Applies to
- ONTAP 9
- Domain Controller
Answer
- In 9.12 and above, you can disable advertising the RC4 encryption type
- In 9.11 and below, you cannot disable RC4 encryption for Kerberos-based communication
- Even when AES encryption for Kerberos-based communication is enabled on a vserver, advertising the RC4 encryption type cannot be disabled
- When AES and RC4 are both enabled, the vserver will always use AES
- Unless the client requests RC4 specifically, then AES is provided instead of RC4
- The strongest encryption type is selected by the DC that provides the Kerberos ticket if multiple are available
Additional Information
- Validating if hardware can upgrade to a version that allows disabling RC4 may be required and can be done using Hardware Universe
- Enabling or disabling AES encryption for Kerberos-based communication
- Configuring strong security for Kerberos-based communication by using AES encryption
- Decrypting the Selection of Supported Kerberos Encryption Types
- Enable or disable AES encryption for Kerberos-based communication
