diff --git a/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/configuration/kerberos-env.xml b/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/configuration/kerberos-env.xml
index d00e59790aa..d00423ce618 100644
--- a/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/configuration/kerberos-env.xml
+++ b/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/configuration/kerberos-env.xml
@@ -126,7 +126,7 @@
The supported list of session key encryption types that should be returned by the KDC.
- aes des3-cbc-sha1 rc4 des-cbc-md5
+ aes256-cts-hmac-sha1-96 aes128-cts-hmac-sha1-96
multiLine
false
diff --git a/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/properties/krb5_conf.j2 b/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/properties/krb5_conf.j2
index 574147f027d..2526046d367 100644
--- a/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/properties/krb5_conf.j2
+++ b/ambari-server/src/main/resources/stacks/BIGTOP/3.2.0/services/KERBEROS/properties/krb5_conf.j2
@@ -23,8 +23,8 @@
dns_lookup_realm = false
dns_lookup_kdc = false
default_ccache_name = /tmp/krb5cc_%{uid}
- #default_tgs_enctypes = {{encryption_types}}
- #default_tkt_enctypes = {{encryption_types}}
+ default_tgs_enctypes = {{encryption_types}}
+ default_tkt_enctypes = {{encryption_types}}
{%- if force_tcp %}
udp_preference_limit = 1
{%- endif -%}