krb5 error code 52 - can't login

Sam Hartman hartmans at MIT.EDU
Thu May 30 11:31:48 EDT 2002

>>>>> "l9phan1" == l9phan1  <l9phan1 at> writes:

    l9phan1> I got the following error message when using kinit
    l9phan1> command: kinit (v5): krb5 error code 52 while getting
    l9phan1> initial credentials.

When a user is in too many groups, the Windows KDC requests that the
client use TCP rather than UDP for the ticket.  MIT does not implement
TCP so it fails.

You may be able to set a registry key on the Windows side setting how
large the packet can be before TCP is used.

More information about the Kerberos mailing list