You upgraded to CentOS 8.3, which includes a rebased Kerberos.
To quote from the RHEL 8.3 release notes:
krb5 rebased to version 1.18.2
The krb5 packages have been upgraded to upstream version 1.18.2. Notable fixes and enhancements include:
- Single- and triple-DES encryption types have been removed.
- Draft 9 PKINIT has been removed as it is not needed for any of the supported versions of Active Directory.
- NegoEx mechanism plug-ins are now supported.
- Hostname canonicalization fallback is now supported (dns_canonicalize_hostname = fallback).
(BZ#1802334)
You didn't say what problems you are having (and you should have!). But I would guess based on experience that you still have ancient stuff in your environment that was using 3DES or DES. Of course all of that stuff should have been reconfigured, upgraded or decommissioned many years ago. Since nobody did, now is the time to do it.