Microsoft-Windows-Security-Kerberos

86 events across 2 channels

Event IDTitleChannel
3Operational
4Operational
5Operational
6Operational
7Operational
8Operational
9Operational
10Operational
11Operational
12Operational
13An error occurred while initializing the smart card logon library.Operational
14Operational
15Operational
16Operational
17Operational
18Operational
19Operational
20Operational
100The service principal name (SPN) %1 is not registered, which caused Kerberos …Operational
101The service principal name (SPN) %1 is registered on multiple accounts which …Operational
102Trust validation of the certificate for the Kerberos Key Distribution Center …Operational
103Trust validation of the client certificate for %1 failed: %2 on KDC.Operational
104The Kerberos Key Distribution Center (KDC) for the domain %1 does not have a …Operational
105The Kerberos client could not retrieve passwords for the group managed service …Operational
106The Kerberos client received a KDC certificate that does not have KDC EKU (not …Operational
107The Kerberos client received a KDC certificate that does not have a matched …Operational
108The Kerberos client could not send a Kerberos proxy request.Operational
109The Kerberos client could not find a suitable credential to use with the …Operational
200The Kerberos client could not locate a domain controller for domain %1: %2.Operational
201Attempt to use Kerberos unconstrained delegation failed.Operational
202Attempt to export TGT session key failed.Operational
203When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies …Operational
204Kerberos does not accept PKINIT KDC replies using public key encryption.Operational
205The KDC used a hash algorithm for the PKINIT protocol that is being audited.Operational
206The Kerberos client used a hash algorithm for the PKINIT protocol that is being …Operational
207The KDC used a hash algorithm for the PKINIT protocol that is not supported on …Operational
208The Kerberos client and KDC could not agree on a policy compliant hash algorithm …Operational
209The Kerberos client has an invalid hash algorithm configuration for PKINIT.Operational
300The Kerberos client discovered domain controller %1 for the domain %2.Operational
301The Kerberos client used credentials from the Credential Manager for the target: …Operational
302The Kerberos client was bound to domain controller %1 for the domain %2 but …Operational
303The Kerberos client updated passwords for the group managed service account.Operational
304The Kerberos client used the DES algorithm to encrypt data.Operational
305Export of TGT attempted through call package.Operational
306Export of supplemental credentials attempted.Operational
307The Kerberos client has discovered a DMSA migration Old Account Name: %1 New …Operational
308Adding machine to the Principals Allowed Managed Password attribute of a DMSA DC …Operational
309Fetching keys for a DMSA using the machine account KDC Used: %1 Domain Name: %2 …Operational
310Machine password migrated from LSA to VBS Enforcement Mode.Operational
311Machine Identity Isolation is currently in enforcement mode.Operational
312Machine password change failed Status: %1 Migration Needed: %2 Policy: %3 Exit …Operational
65541An error occurred while retrieving a digital certificate from the inserted smart …Operational
65542An error occurred in while attempting to verify the inserted smart card.Operational
65543An error occurred while signing a message using the inserted smart card.Operational
65544An error occurred while verifying a signed message using the inserted smart …Operational
65545An error occurred while verifying the digital certificate retrieved from the …Operational
65546An error occurred while encrypting a message using the inserted smart card.Operational
65547An error occurred while decrypting a message using the inserted smart card.Operational
65548An error occurred while building a certificate context.Operational
65550An error occurred while signing a message.Operational
65551An error occurred while verifying a signed message.Operational
65552An error occurred while encrypting a message.Operational
65553An error occurred while decrypting a message.Operational
65554An error occurred while retrieving some provider parameter.Operational
65555An error occurred while generating a random number.Operational
1073741828The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server %1.Operational
1073741829The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server %1.Operational
2147483651A Kerberos error message was received: on logon session %1 Client Time: %2 …Operational
2147483654The Kerberos SSPI package generated an output token of size %1 bytes, which was …Operational
2147483658The Kerberos subsystem currently cannot retrieve tickets from your domain …Operational
2147483660While using your smart card over a VPN connection, the Kerberos subsystem …Operational
2147483661The smart card PIN stored in Credential Manager is missing or invalid.Operational
2147483662The password stored in Credential Manager is invalid.Operational
2147483663The Kerberos SSPI package generated an output token of size %1 bytes, which was …Operational
2147483666The delegated TGT for the user has expired.Operational
2147483667The KDC certificate for the domain controller does not contain the KDC Extended …Operational
2147483668The KDC certificate for the domain controller does not have the DNS name of …Operational
2147483669During Kerberos Network Ticket Logon, the service ticket for Account .Operational
2147483670During Kerberos Network Ticket Logon, the service ticket for Account .Operational
2147483671During Kerberos Network Ticket Logon, the service ticket for Account .Operational
3221225479The digitally signed Privilege Attribute Certificate (PAC) that contains the …Operational
3221225480The domain controller rejected the client certificate of user %2, used for smart …Operational
3221225481The client has failed to validate the domain controller certificate for %2.Operational
3221225483The Distinguished Name in the subject field of your smart card logon certificate …Operational
3221225488The Kerberos SSPI package failed to find the smart card certificate in the …Operational
3221225489The Kerberos SSPI package failed to locate the forest or domain %1 to search.Operational

Event ID 3 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
LogonSession
ClientTime
ServerTime
ErrorCode
ErrorMessage
ExtendedError
ClientRealm
ClientName
ServerRealm
ServerName
TargetName
ErrorText
File
Line
__binLength
binary

Event ID 4 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Server
TargetRealm
Targetname
ClientRealm
__binLength
binary

Event ID 5 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 6 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 7 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 8 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 9 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 10 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 11 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 12 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 13 — An error occurred while initializing the smart card logon library.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while initializing the smart card logon library: %1

Fields

NameDescription
Error
__binLength
binary

Event ID 14 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 15 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 16 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Sigma Rules

  • No Suitable Encryption Key Found For Generating Kerberos Ticket
    Detects errors when a target server doesn't have suitable keys for generating kerberos tickets. This issue can occur for example when a service uses a user account or a computer account that is configured for only DES encryption on a computer that is running Windows 7 which has DES encryption for Kerberos authentication disabled.

Event ID 17 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 18 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 19 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Error
__binLength
binary

Event ID 20 —

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
DomainName
ErrorCode

Event ID 100 — The service principal name (SPN) %1 is not registered, which caused Kerberos authentication to fail: %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The service principal name (SPN) %1 is not registered, which caused Kerberos authentication to fail: %2. Use the setspn command-line tool to register the SPN.

Fields

NameDescription
SPN
ErrorCode

Event ID 101 — The service principal name (SPN) %1 is registered on multiple accounts which caused Kerberos authentication to fail: %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The service principal name (SPN) %1 is registered on multiple accounts which caused Kerberos authentication to fail: %2. Use the setspn command-line tool to identify the accounts and remove the duplicate registrations.

Fields

NameDescription
SPN
ErrorCode

Event ID 102 — Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) %1 failed: %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) %1 failed: %2. Use the CAPI2 diagnostic traces to identify the reason for the validation failure.

Fields

NameDescription
DomainController
ErrorCode

Event ID 103 — Trust validation of the client certificate for %1 failed: %2 on KDC.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Trust validation of the client certificate for %1 failed: %2 on KDC. Use the CAPI2 diagnostic traces to identify the reason for the validation failure.

Fields

NameDescription
ClientUpn
ErrorCode

Event ID 104 — The Kerberos Key Distribution Center (KDC) for the domain %1 does not have a certificate installed or does not support logon using certificates: %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos Key Distribution Center (KDC) for the domain %1 does not have a certificate installed or does not support logon using certificates: %2

Fields

NameDescription
TargetDomain
ErrorCode

Event ID 105 — The Kerberos client could not retrieve passwords for the group managed service account.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client could not retrieve passwords for the group managed service account.

LogonId: %1:%2
DomainName: %3
UserName: %4
Refresh: %5
Current File Time: %6
Error Code: %7

Fields

NameDescription
LogonId
DomainName
UserName
Refresh
Current_File_Time
Error_Code
LuidHighPart
LuidLowPart
CurrentFileTime
ErrorCode

Event ID 106 — The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).

Error Code: %1

Fields

NameDescription
Error_Code
ErrorCode

Event ID 107 — The Kerberos client received a KDC certificate that does not have a matched domain name.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client received a KDC certificate that does not have a matched domain name.

Expected Domain Name: %1
Error Code: %2

Fields

NameDescription
Expected_Domain_Name
Error_Code
ExpectedDomainName
ErrorCode

Event ID 108 — The Kerberos client could not send a Kerberos proxy request.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client could not send a Kerberos proxy request.

ProxyServer:
  ServerName: %1
  ServerPort: %2
  ServerVdir:  %3
Error Code: %4
Status Code: %5

Fields

NameDescription
ServerName[ProxyServer] ServerName.
ServerPort[ProxyServer] ServerPort.
ServerVdir[ProxyServer] ServerVdir.
Error_Code[ProxyServer] Error Code.
Status_Code[ProxyServer] Status Code.
ErrorCode
Status

Event ID 109 — The Kerberos client could not find a suitable credential to use with the authentication proxy: AuthProxy: Proxy: %1 ProxyBypass: %2 Epoch: %3 Suppo...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client could not find a suitable credential to use with the authentication proxy:

AuthProxy:
  Proxy: %1
  ProxyBypass: %2
  Epoch: %3
  Supported Schemes: %4
  First Scheme: %5
Digest Credential:
  Initialized: %6
  DomainAndUserName: %7
  Epoch: %8
Basic Credential:
  Initialized: %9
  DomainAndUserName: %10
  Epoch: %11

Fields

NameDescription
Proxy[AuthProxy] Proxy.
ProxyBypass[AuthProxy] ProxyBypass.
Epoch[AuthProxy] Epoch.
Supported_Schemes[AuthProxy] Supported Schemes.
First_Scheme[AuthProxy] First Scheme.
Initialized[Digest Credential] Initialized.
DomainAndUserName[Digest Credential] DomainAndUserName.
Epoch[Digest Credential] Epoch.
Initialized[Basic Credential] Initialized.
DomainAndUserName[Basic Credential] DomainAndUserName.
Epoch[Basic Credential] Epoch.
ProxyEpoch
SupportedSchemes
FirstScheme
DigestCredInitialized
DigestCredDomainAndUserName
DigestCredEpoch
BasicCredInitialized
BasicCredDomainAndUserName
BasicCredEpoch

Event ID 200 — The Kerberos client could not locate a domain controller for domain %1: %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client could not locate a domain controller for domain %1: %2. Kerberos authentication requires communicating with a domain controller.

Fields

NameDescription
TargetDomain
ErrorCode

Event ID 201 — Attempt to use Kerberos unconstrained delegation failed.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Attempt to use Kerberos unconstrained delegation failed.

Target server: %1
Supplied user: %2
Supplied domain: %3
PID of client process: %4
Name of client process: %5
LUID of client process: %6
User identity of client process: %7
Domain name of user identity of client process: %8
Mechanism OID: %9

Kerberos unconstrained delegation is not allowed for this user. For more information, see https://go.microsoft.com/fwlink/?linkid=856824.

Fields

NameDescription
TargetName
UserName
DomainName
CallerPID
ProcessName
ClientLUID
ClientUserName
ClientDomainName
MechanismOID

Event ID 202 — Attempt to export TGT session key failed.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Attempt to export TGT session key failed.

Target server: %1
Supplied user: %2
Supplied domain: %3
PID of client process: %4
Name of client process: %5
LUID of client process: %6
User identity of client process: %7
Domain name of user identity of client process: %8
Mechanism OID: %9

This device does not allow exporting TGT session keys. For more information, see https://go.microsoft.com/fwlink/?linkid=856825.

Fields

NameDescription
TargetName
UserName
DomainName
CallerPID
ProcessName
ClientLUID
ClientUserName
ClientDomainName
MechanismOID

Event ID 203 — When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be expo...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

When Credential Guard is enabled, Kerberos does not accept PKINIT KDC replies using public key encryption to ensure Kerberos tickets cannot be exported from the device. For more information, see https://go.microsoft.com/fwlink/?linkid=856823.

Event ID 204 — Kerberos does not accept PKINIT KDC replies using public key encryption.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Kerberos does not accept PKINIT KDC replies using public key encryption.

Event ID 205 — The KDC used a hash algorithm for the PKINIT protocol that is being audited.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The KDC used a hash algorithm for the PKINIT protocol that is being audited: %1.

Fields

NameDescription
Algorithm

Event ID 206 — The Kerberos client used a hash algorithm for the PKINIT protocol that is being audited.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client used a hash algorithm for the PKINIT protocol that is being audited: %1.

Fields

NameDescription
Algorithm

Event ID 207 — The KDC used a hash algorithm for the PKINIT protocol that is not supported on the client.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The KDC used a hash algorithm for the PKINIT protocol that is not supported on the client: %1.

Fields

NameDescription
Algorithm

Event ID 208 — The Kerberos client and KDC could not agree on a policy compliant hash algorithm for PKINIT.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client and KDC could not agree on a policy compliant hash algorithm for PKINIT. 

Client supported algorithms: { %1 }
KDC supported algorithms: { %2 }

Fields

NameDescription
ClientAlgorithms
KdcAlgorithms

Event ID 209 — The Kerberos client has an invalid hash algorithm configuration for PKINIT.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client has an invalid hash algorithm configuration for PKINIT. This might result in PKINIT failures.

Event ID 300 — The Kerberos client discovered domain controller %1 for the domain %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client discovered domain controller %1 for the domain %2.

Fields

NameDescription
DomainController
TargetDomain

Event ID 301 — The Kerberos client used credentials from the Credential Manager for the target: '.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client used credentials from the Credential Manager for the target: '%1'.

Fields

NameDescription
Target

Event ID 302 — The Kerberos client was bound to domain controller %1 for the domain %2 but could not access this domain controller at the time.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client was bound to domain controller %1 for the domain %2 but could not access this domain controller at the time.

    DesiredFlags: %3
    CacheFlags: %4
    ErrorCode: %5

Fields

NameDescription
DesiredFlags
CacheFlags
ErrorCodeDesiredFlags.
DomainController
TargetDomain

Event ID 303 — The Kerberos client updated passwords for the group managed service account.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client updated passwords for the group managed service account.

LogonId: %1:%2
DomainName: %3
UserName: %4
Update Current Passwords: %5
Update Old Passwords: %6
Refresh: %7
Previous File Time: %8
Current File Time: %9

Fields

NameDescription
LogonId
DomainName
UserName
Update_Current_Passwords
Update_Old_Passwords
Refresh
Previous_File_Time
Current_File_Time
LuidHighPart
LuidLowPart
UpdateCurrent
UpdateOld
LastFileTime
CurrentFileTime

Event ID 304 — The Kerberos client used the DES algorithm to encrypt data.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client used the DES algorithm to encrypt data. This is unsupported with Credential Guard.

Event ID 305 — Export of TGT attempted through call package.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Export of TGT attempted through call package. This is unsupported with Credential Guard.

Process Name:%1
Service Host Tag:%2

Fields

NameDescription
Process_Name
Service_Host_Tag
ProcessName
SvchostTag

Event ID 306 — Export of supplemental credentials attempted.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Export of supplemental credentials attempted. This is unsupported with Credential Guard.

Process Name:%1
Service Host Tag:%2

Fields

NameDescription
Process_Name
Service_Host_Tag
ProcessName
SvchostTag

Event ID 307 — The Kerberos client has discovered a DMSA migration Old Account Name: %1 New Account Name: %2 Domain Name: %3 Status: %4 Migration Complete: %5.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client has discovered a DMSA migration
Old Account Name: %1
New Account Name: %2
Domain Name: %3
Status: %4
Migration Complete: %5

Fields

NameDescription
OldAccount
NewAccount
DomainName
Status
MigrationComplete

Event ID 308 — Adding machine to the Principals Allowed Managed Password attribute of a DMSA DC Used: %1 DMSA Distinguished Name: %2 Linked Account: %3 Domain Nam...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Adding machine to the Principals Allowed Managed Password attribute of a DMSA
DC Used: %1
DMSA Distinguished Name: %2
Linked Account: %3
Domain Name:  %4
Previously Authorized: %5
Status: %6

Fields

NameDescription
DC
DN
Account
Domain
PreviouslyAuthorized
Status

Event ID 309 — Fetching keys for a DMSA using the machine account KDC Used: %1 Domain Name: %2 Account Name: %3 Fetch Time: %4 Expiration Time: %5 Keys Updated: %...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Fetching keys for a DMSA using the machine account
KDC Used: %1
Domain Name: %2
Account Name: %3
Fetch Time:  %4
Expiration Time: %5
Keys Updated: %6
Ntlm Updated: %7
Status: %8

Fields

NameDescription
KDC
Domain
Account
Fetch
Expiration
KeyUpdate
NtlmUpdate
Status

Event ID 310 — Machine password migrated from LSA to VBS Enforcement Mode.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Machine password migrated from LSA to VBS
Enforcement Mode: %1

Fields

NameDescription
EnforcementMode

Event ID 311 — Machine Identity Isolation is currently in enforcement mode.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Machine Identity Isolation is currently in enforcement mode. To go back to disabled/audit mode, you must manually unjoin and rejoin the domain.

Event ID 312 — Machine password change failed Status: %1 Migration Needed: %2 Policy: %3 Exit Reason: %4.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

Machine password change failed
Status: %1
Migration Needed: %2
Policy: %3
Exit Reason: %4

Fields

NameDescription
Status
MigrationNeeded
EnforcementMode
ExitReason

Event ID 65541 — An error occurred while retrieving a digital certificate from the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while retrieving a digital certificate from the inserted smart card. %1

Fields

NameDescription
Error
binary

Event ID 65542 — An error occurred in while attempting to verify the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred in while attempting to verify the inserted smart card: %1

Fields

NameDescription
Error
binary

Event ID 65543 — An error occurred while signing a message using the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while signing a message using the inserted smart card: %1

Fields

NameDescription
Error
binary

Event ID 65544 — An error occurred while verifying a signed message using the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while verifying a signed message using the inserted smart card: %1

Fields

NameDescription
Error
binary

Event ID 65545 — An error occurred while verifying the digital certificate retrieved from the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while verifying the digital certificate retrieved from the inserted smart card: %1

Fields

NameDescription
Error
binary

Event ID 65546 — An error occurred while encrypting a message using the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while encrypting a message using the inserted smart card: %1

Fields

NameDescription
Error
binary

Event ID 65547 — An error occurred while decrypting a message using the inserted smart card.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while decrypting a message using the inserted smart card: %1

Fields

NameDescription
Error
binary

Event ID 65548 — An error occurred while building a certificate context.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while building a certificate context: %1

Fields

NameDescription
Error
binary

Event ID 65550 — An error occurred while signing a message.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while signing a message: %1

Fields

NameDescription
Error
binary

Event ID 65551 — An error occurred while verifying a signed message.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while verifying a signed message: %1

Fields

NameDescription
Error
binary

Event ID 65552 — An error occurred while encrypting a message.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while encrypting a message: %1

Fields

NameDescription
Error
binary

Event ID 65553 — An error occurred while decrypting a message.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while decrypting a message: %1

Fields

NameDescription
Error
binary

Event ID 65554 — An error occurred while retrieving some provider parameter.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while retrieving some provider parameter: %1

Fields

NameDescription
Error
binary

Event ID 65555 — An error occurred while generating a random number.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

An error occurred while generating a random number: %1

Fields

NameDescription
Error
binary

Event ID 1073741828 — The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server %1.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server %1. The target name used was %3. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (%2) is different from the client domain (%4), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server.

Fields

NameDescription
Server
TargetRealm
Targetname
ClientRealm
binary

Event ID 1073741829 — The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server %1.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server %1. This indicates that the ticket presented to that server is not yet valid (due to a discrepancy between ticket and server time. Contact your system administrator to make sure the client and server times are synchronized, and that the time for the Key Distribution Center Service (KDC) in realm %2 is synchronized with the KDC in the client realm.

Fields

NameDescription
Server
KDCRealm
binary

Event ID 2147483651 — A Kerberos error message was received: on logon session %1 Client Time: %2 Server Time: %3 Error Code: %4 %5 Extended Error: %6 Client Realm: %7 Cl...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

A Kerberos error message was received:
 on logon session %1
 Client Time: %2
 Server Time: %3
 Error Code: %4 %5
 Extended Error: %6
 Client Realm: %7
 Client Name: %8
 Server Realm: %9
 Server Name: %10
 Target Name: %11
 Error Text: %12
 File: %13
 Line: %14
 Error Data is in record data.

Fields

NameDescription
Client_Time
Server_Time[A Kerberos error message was received] Client Time.
Error_Code[A Kerberos error message was received] Server Time.
Extended_Error[A Kerberos error message was received] Error Code.
Client_Realm
Client_Name[A Kerberos error message was received] Extended Error.
Server_Realm[A Kerberos error message was received] Client Realm.
Server_Name[A Kerberos error message was received] Client Name.
Target_Name[A Kerberos error message was received] Server Realm.
Error_Text[A Kerberos error message was received] Server Name.
File[A Kerberos error message was received] Target Name.
Line[A Kerberos error message was received] Error Text.
LogonSession
ClientTime
ServerTime
ErrorCode
ErrorMessage
ExtendedError
ClientRealm
ClientName
ServerRealm
ServerName
TargetName
ErrorText
binary

Event ID 2147483654 — The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by ...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by process id %3.
 
 The output SSPI token size is probably the result of the user %4 being a member of a large number of groups.
 
 It is recommended to minimize the number of groups a user belongs to. If the problem can not be corrected by reducing the group memberships of this user, contact your system administrator to increase the maximum token size, which is configured on each computer individually using the registry value: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\MaxTokenSize.

Fields

NameDescription
NeededSize
ActualSize
ClientProcessID
ClientName
binary

Event ID 2147483658 — The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol. This is typically due to network problems. Contact your system administrator.

Event ID 2147483660 — While using your smart card over a VPN connection, the Kerberos subsystem encountered an error.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

While using your smart card over a VPN connection, the Kerberos subsystem encountered an error. Typically, this indicates the card has been pulled from the card reader during the VPN session. One possible solution is to close the VPN connection, reinsert the card, and establish the connection again.

Event ID 2147483661 — The smart card PIN stored in Credential Manager is missing or invalid.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The smart card PIN stored in Credential Manager is missing or invalid. The smart card PIN is stored in memory only for the current interactive logon session, and is deleted if the card is removed from the card reader or when the user logs off. To resolve this error, keep the card in the reader, open Credential Manager in Control Panel, and reenter the PIN for the credential %1.

Fields

NameDescription
Username
binary

Event ID 2147483662 — The password stored in Credential Manager is invalid.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The password stored in Credential Manager is invalid. This might be caused by the logged on user changing the password from this computer or a different computer. To resolve this error, open Credential Manager in Control Panel, and reenter the password for the credential %1.

Fields

NameDescription
Username
binary

Event ID 2147483663 — The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by ...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by process id %3.
 
 The application needs to be modified to supply a token buffer of size at least %4 bytes.

Fields

NameDescription
NeededSize
ActualSize
ClientProcessID
RequiredSize
binary

Event ID 2147483666 — The delegated TGT for the user has expired.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The delegated TGT for the user (%2) has expired. A renewal was attempted and failed with error %8. The server logon session (%1) has stopped delegating the user's credential. For future unconstrained delegation to succeed, the user needs to authenticate again to the server. 

TGT Details:
    Client: %2
    Server: %3
    Flags: %4
    Start Time: %5
    End Time: %6
    Renew Until: %7

Fields

NameDescription
Client
Server[TGT Details] Client.
Flags[TGT Details] Server.
Start_Time[TGT Details] Flags.
End_Time[TGT Details] Start Time.
Renew_Until[TGT Details] End Time.
Luid
ClientPrincipalName
ServicePrincipalName
TicketFlags
StartTime
EndTime
RenewUntil
ErrorCode

Event ID 2147483667 — The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.3.6.1.5.2.3.5: Error Code %1. The domain administrator will need to obtain a certificate with the KDC EKU for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template.

Fields

NameDescription
ErrorCode

Event ID 2147483668 — The KDC certificate for the domain controller does not have the DNS name of domain %1 in the Subject Alternative Name (SAN) attribute: Error Code %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The KDC certificate for the domain controller does not have the DNS name of domain %1 in the Subject Alternative Name (SAN) attribute: Error Code %2. The domain administrator will need to obtain a KDC certificate with the DNS domain name in the SAN attribute for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template.

Fields

NameDescription
DomainName
ErrorCode

Event ID 2147483669 — During Kerberos Network Ticket Logon, the service ticket for Account .

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
param1
param2
param3
param4

Event ID 2147483670 — During Kerberos Network Ticket Logon, the service ticket for Account .

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
Reason
ErrorCode

Event ID 2147483671 — During Kerberos Network Ticket Logon, the service ticket for Account .

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Fields

NameDescription
param1
param2

Event ID 3221225479 — The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client %1 in realm %2 could not be valid...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client %1 in realm %2 could not be validated.
 
 This error is usually caused by domain trust failures; Contact your system administrator.

Fields

NameDescription
ClientName
Realm
binary

Event ID 3221225480 — The domain controller rejected the client certificate of user %2, used for smart card logon.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The domain controller rejected the client certificate of user %2, used for smart card logon. The following error was returned from the certificate validation process: %1.

Fields

NameDescription
Name
Message
binary

Event ID 3221225481 — The client has failed to validate the domain controller certificate for %2.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The client has failed to validate the domain controller certificate for %2. The following error was returned from the certificate validation process: %1.

Fields

NameDescription
Name
Message
binary

Event ID 3221225483 — The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate do...

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate domain on an non-domain joined computer. Contact your system administrator.

Event ID 3221225488 — The Kerberos SSPI package failed to find the smart card certificate in the certificate store.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos SSPI package failed to find the smart card certificate in the certificate store. To remedy this failure, logon as user %1 and insert the smart card into the smart card reader, then use the Certificates snap-in to verify that the smart card certificate is in the user's personal certificate store.

Fields

NameDescription
Username
binary

Event ID 3221225489 — The Kerberos SSPI package failed to locate the forest or domain %1 to search.

Provider
Microsoft-Windows-Security-Kerberos
Channel
Operational

Message

The Kerberos SSPI package failed to locate the forest or domain %1 to search.  Ensure that the Use forest search order Group Policy is correctly configured, and that this forest or domain is available.

Fields

NameDescription
Forest
binary