Hello @Daisy Zhou ,
Last question, Since AES is enabled by default.
- Require to enable for child domain with domain trust?
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hello,
I need some advice here, as the current environment contain Parent domain & 2 child domains. Due to some security policy RC4 has been disabled for all domain controllers. I noticed while doing health check or manual repadmin /replsum etc.
Seem to getting AD health check is unhealthy.
[DC2] DsBindWithSpnEx() failed with error 5,
Access is denied..
Warning: DC2 is the Schema Owner, but is not responding to DS RPC Bind.
[DC1] DsBindWithSpnEx() failed with error 5,
Access is denied..
Warning: DC1 is the PDC Owner, but is not responding to DS RPC Bind
Does it necessary to enable AES Encryption?
Hello @Daisy Zhou ,
Last question, Since AES is enabled by default.
Hello @RussellAng-0425,
Thank you for your update.
I am sorry, I cannot explain it clearly.
Q: Last question, Since AES is enabled by default. Require to enable for child domain with domain trust?
A: Yes, AES is enabled by default in the same domain.
It is required to enable for Parent-Child domain with domain trust.
Parent domain and child domain use the default Parent-Child trusts, but this trusts by default uses RC4 as ETYPE for Kerberos.
Now RC4 is disabled, so if you want to enable AES on this trust you need to enable this flag (disabled by default) in the trusts properties:
For more information, please refer to link below.
Tough Questions Answered: Can I disable RC4 Etype for Kerberos on Windows 10?
https://techcommunity.microsoft.com/t5/itops-talk-blog/tough-questions-answered-can-i-disable-rc4-etype-for-kerberos-on/ba-p/382718
Hope the information above is helpful to you.
Should you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.