| Previous | Next |
| STATUS_KDC_UNABLE_TO_REFER | STATUS_SHUTDOWN_IN_PROGRESS |
STATUS_KDC_UNKNOWN_ETYPE
Encryption negotiation is part of compatibility
STATUS_KDC_UNKNOWN_ETYPE means that the Key Distribution Center cannot satisfy the requested Kerberos encryption type. It is a compatibility and policy issue, not a generic communications failure. The client, account, service, domain controller and, in cross-domain scenarios, the trust path must have an overlapping allowed encryption capability. Removing an older type on one side without aligning the other participants can make a previously working authentication flow fail.
Microsoft documents a concrete trust scenario where RC4 is disabled while AES types remain enabled and NTLM is also disabled, producing an unsupported-encryption-type failure. RFC 4120 supplies the protocol context, while Windows KILE describes the Microsoft Kerberos implementation details.
What to compare
- Determine which request failed: initial logon, service ticket, machine account operation or cross-domain trust authentication.
- Inspect the encryption types allowed for the affected account, service principal, domain controller and trust, including policy changes made during hardening.
- Compare a working client or domain path with the failing path instead of broadly re-enabling legacy encryption.
- Plan changes as a compatibility migration, with test accounts and rollback evidence, because encryption settings can affect many clients and services.
References
- Microsoft Open Specifications: NTSTATUS reference
- Microsoft: unsupported Kerberos encryption type
- RFC 4120: Kerberos V5
- Microsoft Open Specifications: Kerberos Protocol Extensions (MS-KILE)
Looking for a different code? Search another status or error code.