RFC 4537:Kerberos Cryptosystem Negotiation Extensi...
RFC-Ref

encryption


Click on the red underlined text to get to the source

... Kerberos Distribution Center (KDC) must limit the ticket session key encryption type (enctype) chosen for a given server to one it believes is supported by both the client ...


... The client's enctype list and the server's reply enctype are part of encrypted data; thus, the security considerations are the same as those of the Kerberos ...
... security considerations are the same as those of the Kerberos encrypted data. Both the EtypeList and the server's sub-session key ...
... enctype can also discover the key for the stronger enctype. The advantage of this extension is to minimize the amount of cipher text encrypted under a weak enctype to which an attacker has access. ...


... Raeburn, K., "Encryption and Checksum Specifications for Kerberos 5", RFC 3961prop ...



Google
Web
RFC-Ref