The translations below need to be checked and inserted above into the appropriate translation tables, removing any numbers.
Numbers do not necessarily match those in definitions.
Solution: You must type the principal and policy names in the Name field to work on them, or you need to log in with a principal that has the appropriate privileges.
Cause: The password that you specified has been used before by this principal.
Solution: Determine if you are either requesting an option that the KDC does not allow or a type of ticket that is not available. For example, the request to the KDC did not have an IP address in its request.
Or forwarding was requested, but the KDC did not allow it.
The realms might not have the correct trust relationships set up.
Solution: Make sure that the realms you are using have the correct trust relationships.
Solution: Make sure that the host name is defined in DNS and that the host-name-to-address and address-to-host-name mappings are consistent.
Cause: The ticket sent did not have the correct cross-realms.
Solution: Make sure that the server you are communicating with is in the same realm as the client, or that the realm configurations are correct.