Kerberos Error Messages

GSSAPI Error Codes

GSSAPI Error Codes

Generic GSSAPI Errors:

1.GSS_KRB5_S_G_BAD_SERVICE_NAME: /* "No @ in SERVICE-NAME name string" */

2.GSS_KRB5_S_G_BAD_STRING_UID: /* "STRING-UID-NAME contains nondigits" */

3.GSS_KRB5_S_G_NOUSER: /* "UID does not resolve to username" */

4.GSS_KRB5_S_G_VALIDATE_FAILED: /* "Validation error" */

5.GSS_KRB5_S_G_BUFFER_ALLOC: /* "Couldn’t allocate gss_buffer_t data" */

6.GSS_KRB5_S_G_BAD_MSG_CTX: /* "Message context invalid" */

7.GSS_KRB5_S_G_WRONG_SIZE: /* "Buffer is the wrong size" */

8.GSS_KRB5_S_G_BAD_USAGE: /* "Credential usage type is unknown" */

9.GSS_KRB5_S_G_UNKNOWN_QOP: /* "Unknown quality of protection specified" */

Kerberos 5 GSSAPI Errors:

1.GSS_KRB5_S_KG_CCACHE_NOMATCH: /* "Principal in credential cache does not match desired name" */

2.GSS_KRB5_S_KG_KEYTAB_NOMATCH: /* "No principal in keytab matches desired name" */

3.GSS_KRB5_S_KG_TGT_MISSING: /* "Credential cache has no TGT" */

4.GSS_KRB5_S_KG_NO_SUBKEY: /* "Authenticator has no subkey" */

5.GSS_KRB5_S_KG_CONTEXT_ESTABLISHED: /* "Context is already fully established" */

6.GSS_KRB5_S_KG_BAD_SIGN_TYPE: /* "Unknown signature type in token" */

Appendix E

133