When the user supplies the correct password, but has a timestamp that is out of bounds, the server should reply with a clock skew error rather than a preauth required error. To generate a diff of this commit: cvs diff -r5.244 -r5.245 krb5/src/kdc/ChangeLog cvs diff -r5.32 -r5.33 krb5/src/kdc/kdc_preauth.c