The following table lists the minor status messages that are returned in Kerberos v5 for status code 2.
Table B–6 Kerberos v5 Status Codes 2
Minor Status |
Value |
Meaning |
---|---|---|
KRB5KDC_ERR_TGT_REVOKED |
-1765328364L |
TGT has been revoked |
KRB5KDC_ERR_CLIENT_NOTYET |
-1765328363L |
Client not yet valid, try again later |
KRB5KDC_ERR_SERVICE_NOTYET |
-1765328362L |
Server not yet valid, try again later |
KRB5KDC_ERR_KEY_EXP |
-1765328361L |
Password has expired |
KRB5KDC_ERR_PREAUTH_FAILED |
-1765328360L |
Preauthentication failed |
KRB5KDC_ERR_PREAUTH_REQUIRED |
-1765328359L |
Additional preauthentication required |
KRB5KDC_ERR_SERVER_NOMATCH |
-1765328358L |
Requested server and ticket don't match |
KRB5PLACEHOLD_27 through KRB5PLACEHOLD_30 |
-1765328357L through -1765328354L |
KRB5 error codes 27 through 30 (reserved) |
KRB5KRB_AP_ERR_BAD_INTEGRITY |
-1765328353L |
Decrypt integrity check failed |
KRB5KRB_AP_ERR_TKT_EXPIRED |
-1765328352L |
Ticket expired |
KRB5KRB_AP_ERR_TKT_NYV |
-1765328351L |
Ticket not yet valid |
KRB5KRB_AP_ERR_REPEAT |
-1765328350L |
Request is a replay |
KRB5KRB_AP_ERR_NOT_US |
-1765328349L |
The ticket isn't for us |
KRB5KRB_AP_ERR_BADMATCH |
-1765328348L |
Ticket/authenticator do not match |
KRB5KRB_AP_ERR_SKEW |
-1765328347L |
Clock skew too great |
KRB5KRB_AP_ERR_BADADDR |
-1765328346L |
Incorrect net address |
KRB5KRB_AP_ERR_BADVERSION |
-1765328345L |
Protocol version mismatch |
KRB5KRB_AP_ERR_MSG_TYPE |
-1765328344L |
Invalid message type |
KRB5KRB_AP_ERR_MODIFIED |
-1765328343L |
Message stream modified |
KRB5KRB_AP_ERR_BADORDER |
-1765328342L |
Message out of order |
KRB5KRB_AP_ERR_ILL_CR_TKT |
-1765328341L |
Illegal cross-realm ticket |
KRB5KRB_AP_ERR_BADKEYVER |
-1765328340L |
Key version is not available |