To clarify we are only removing aes256 from the default supported_enctypes (KDC) not from default_{tkt,tgs}_enctypes or permitted_enctypes.