I have installed Windows Server 2022 with kerberos authentication. We are trying to connect to this server from a java based RDP client. Connection is failing with error KRB5KDC_ERR_ETYPE_NOSUPP from server

Sai Prasad Kolli 0 Reputation points
2023-05-22T15:09:10.1566667+00:00

I have installed Windows Server 2022 with kerberos authentication.

We are trying to connect to this server from a java based RDP client. Connection is failing with error KRB5KDC_ERR_ETYPE_NOSUPP from server. Below is the snapshot of the network traffic.

The error is coming from server.

Screenshot of client encryption type is also attached.

AES encryption type is enabled for the user.

Is there any configuration to enable debug logging for kerberos to see what encryption types are supported on server. How to configure kerberos encryption type on Windows 2022 server.

wiresharkkerberosclient

wiresharkkerberos

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
9,510 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,427 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 26,656 Reputation points
    2023-05-23T11:34:07.4233333+00:00

    Hello Sai,

    Thank you for your question and for reaching out with your question today.

    The following article outlines what encryption types are compatible with Kerberos:

    https://learn.microsoft.com/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos

    You can find what types are in use under:

    Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options

    If the reply was helpful, please don’t forget to upvote or accept as answer.

    Best regards.


  2. Sai Prasad Kolli 0 Reputation points
    2023-05-23T16:39:53.5666667+00:00

    We have this setting configured to use all encryption types.

    Also this machine is a domain controller.

    Even with this setting we get the same error.

    0 comments No comments