10000 Failed to copy ANSI to Unicode string '%hs'.\n
10001 Failed to make unicode string from '%hs'.\n
10002 Failed to allocate keytab component vector
10003 Overflow in salt computation %hs:%d\n
10004 Error occurred when copying password to Unicode buffer %hs:%d\n
10005 Error occurred when copying principal to Unicode buffer %s:%d\n
10006 Error occurred when copying realm name to Unicode buffer %s:%d\n
10007 Using supplied salt.\n
10008 Building salt with principalname %wZ and domain %wZ (encryption type %d)...\n
10009 Not written: argument is of unhandled size (%d)\n
10010 \n ** Failed to read Keytab %hs's leading bytes: 0x%x\n
10011 Keytab version: 0x%x\n
10012 keysize %d
10016 ptype %d
10018 vno %d
10019 etype 0x%x
10020 keylength %d
10021 %hs is one of: \n
10022 Press [ENTER] to continue
10023 Prints this message.
10024 [ undocumented suboption ]
10025 Terminates optionlist.
10026 (or set environment variable '%hs')
10027 ERROR: cannot format for %hs %hs %hs -- STACK SPACE EXHAUSTED\n
10028 Command line options:\n\n
10029 %hs: enum value '%hs' is not known.\n
10030 one or more of the\n following, separated by '|' or ','
10031 one of the following values
10032 Error: argument for option '%hs' must be %ws:\n
10033
10034 Please submit a shorter principal name.\n
10035 Please submit a shorter password.\n
10036 Existing keytab: \n\n
10037 Keytab read failed!\n
10038 Generated password: %hs\n
10039 ERROR: /out parameter requires a password.\n Specify /pass or +rndPass.\n
10040 ERROR: /out parameter requires a principal name.\n Specify /princ to provide one.\n
10041 the principal
10042 ktpass:failed getting target domain for specified user.\n
10043 Could not locate user.\n
10044 WARNING: Account %hs is not a normal user account (uacFlags=0x%x).\n
10045 WARNING: Cannot determine the account type for %hs.\n
10046 WARNING: Failed to set UPN %hs on %hs.\n kinits to '%hs' will fail.\n
10047 Successfully mapped %hs to %hs.\n
10048 Type the password for %hs:
10049 failed to read password.\n
10050 \nType the password again to confirm:
10051 failed to read confirmation password.\n
10052 The passwords you type must match exactly.\n
10053 Failed to turn off echo input for password entry: 0x%x\n
10054 Failed to retrieve console mode settings: 0x%x.\n
10055 Failed to copy ASCII username to Unicode.\n
10056 ERROR: Failed to initialize account name
10057 WARNING: Account %hs is not a user account (uacflags=0x%x).\n
10058 WARNING: Resetting %hs's password may cause authentication problems if %hs is being used as a server.\n
10059 Failed to retrieve user info for %ws: 0x%x.\n
10060 Aborted.\n
10061 WARNING: pType and account type do not match. This might cause problems.\n
10062 Failed to create key for keytab. Quitting.\n
10063 Failed to create key for keytab. Continuing...\n
10064 Failed to allocate keytable.\n
10065 Key created.\n
10066 Failed to add entry to keytab.\n
10067 Output keytab to %hs:\n
10068 \n\nFailed to write keytab file %hs.\n
10069 Account %hs has been set for DES-only encryption.\n
10070 To make this take effect, you must change %hs's password manually.\n
10071 \nWARNING: No principal name specified.\n
10072 auto: \n
10073 YES
10074 NO
10075 EOF on stdin. Assuming you mean no.\n
10076 EOF at console. Assuming you mean no.\n
10077 Your response, %02x ('%c'), doesn't make sense.\n'Y' and 'N' are the only acceptable responses.
10078 Exiting.\n
10079 Do you really want to delete any previous servicePrincipalName values on %hs
10080 Reset %hs's password
10081 Cannot bind to default domain: 0x%x\n
10082 Cannot locate the user %hs. Will try the local domain.\n
10083 Cannot DsCrackNames %hs: 0x%x\n
10084 '%hs' has %ld matches -- it needs to be unique!\n
10085 Cannot allocate memory\n
10086 DsCrackNames returned 0x%x in the name entry for %hs.\n
10087 Couldn't return username portion of '%hs' -- out of memory.\n
10088 Cannot DsGetDcName for '%hs': 0x%x\n
10089 Targeting domain controller: %ws\n
10090 Error copying password to quoted form\n
10091 Password succesfully set!\n
10092 Password set failed! 0x%08x\n
10093 Error copying ASCII password to Unicode\n
10094 Error copying ASCII DN to Unicode\n
10095 Failed to query kvno attribute from the DC.\nKtpass cannot continue.\n
10096 time() failed: 0x%x\nCannot seed random number generator with current time.\n
10097 Could not allocate %ld chars for random password.\n
10098 [y/n]?
10099 most useful args
10100 Keytab to produce
10101 Principal name (user@REALM)
10102 password to use
10103 use '*' to prompt for password.
10104 ... or use +rndPass to generate a random password
10105 minimum length for random password (def:15)
10106 maximum length for random password (def:256)
10107 display the password when generated.
10108 less useful stuff
10109 map princ (above) to this user account (default: don't)
10110 how to set the mapping attribute (default: add it)
10111 Set account for des-only encryption (default:don't)
10112 Keytab to read/digest
10113 options for key generation
10114 Cryptosystem to use
10115 Iteration Count used for AES encryption
10116 Default: ignored for non-AES, 4096 for AES
10117 principal type in question
10118 Override Key Version Number
10119 Default: query DC for kvno. Use /kvno 1 for Win2K compat.
10120 +Answer answers YES to prompts. -Answer answers NO.
10121 Which DC to use. Default:detect
10122 keytab version (def 0x502). Leave this alone.
10123 raw salt to use when generating key (not needed)
10124 show us the MIT salt being used to generate the key
10125 Set the UPN in addition to the SPN. Default DO.
10126 Set the user's password if supplied.
10127 for compatibility
10128 default 128-bit encryption
10129 AES256-CTS-HMAC-SHA1-96
10130 AES128-CTS-HMAC-SHA1-96
10131 All supported types
10132 The general ptype-- recommended
10133 user service instance
10134 host service instance
10135 add value (default)
10136 set value
10137 doing nothing.\nspecify /pass and/or /mapuser to either \nmake a key with the given password or \nmap a user to a particular SPN, respectively.\n
10138 principal %hs doesn't contain an '@' symbol.\nLooking for something of the form:\nfoo@BAR.COM or xyz/foo@BAR.COM \n^ ^\n| |\n+--------------------+---- I didn't find these.\n
10139 KTPASS: Could not determine the correct principal type.\nIf this keytab is intended for a computer account, please use /ptype KRB5_NT_SRV_HST\nIf this keytab is intended for a user account, please use /ptype KRB5_NT_PRINCIPAL\n
10140 WARNING: Unable to set SPN mapping data.\nIf %hs already has an SPN mapping installed for %hs, this is no cause for concern.\n
10141 NOTE: creating a keytab but not mapping principal to any user.\nFor the account to work within a Windows domain, the\nprincipal must be mapped to an account, either at the\ndomain level (with /mapuser) or locally (using ksetup)\nIf you intend to map %hs to an account through other means\nor don't need to map the user, this message can safely be ignored.\n
10142 WARNING: The Key version used by Windows (%ld) is too big\nto be encoded in a keytab without truncating it to %ld.\nThis is due to a limitation of the keytab file format\nand may lead to interoperability issues.\n\nDo you want to proceed and truncate the version number
10143 The %hs attribute does not exist on the target DC.\nAssuming this is a Windows 2000 domain, and setting\nthe Key Version Number in the Keytab to 1.\n\nSupply '/kvno 1' on the command line to skip this message.\n
10144 option %hs:%hs must be specified and is missing.\n
10145 option %s must be specified and is missing.\n
10146 unknown option '%hs'.\n
10147 Parser: option '%hs' is missing its argument.\n
10148 Parser: argument '%hs' is not a number.\n
10149 Internal error: option '%hs' has bad type 0x%x. Skipping this option.\n
10150 Internal error: option '%hs' has unknown type 0x%x. Skipping this option.\n
10151 Unexpected arguments state!\n
10152 ParseOptions: %hs should be of the form %hs:option (:option:option...)\n
10153 ERROR: empty berval structure returned when parsing %ws attribute.\n
10154 ERROR: nonunique berval structure returned when parsing %ws attribute.\n
10155 Failed to retrieve values for property %ws: 0x%x.\n
10156 WARNING: Failed to disable referral chasing, possibly multiple entries can be found\n
10157 WARNING: search term '%ws' produced no results.\n
10158 %2ld. <Unknown DN: 0x%x>\n
10159 Failed to get DN from search result: 0x%x\n
10160 FAILED: ldap_search_s failed for search term '%ws': 0x%x
10161 FAILED: default naming context does not include requisite attribute %ws.\n
10162 FAILED: unable to query default naming context: 0x%x.\n
10163 Failed to modify %ws attribute to %ld (0x%x) on %ws: 0x%x\n
10164 Using legacy password setting method\n
10165 FAIL: ldap_bind_s failed: 0x%x.\n
10166 FAIL: ldap_open failed for default server: 0x%x.\n
10167 too many values (expected one, got %ld) for %hs.\n
10168 ldap_get_values failed: 0x%x.\n
10169 ldap_first_entry failed: 0x%x.\n
10170 ldap_search failed (0x%x). Couldn't search for base DN.\n
10171 Failed to bind to DSA: 0x%x.\n
10172 Failed to contact DSA: 0x%x.\n
10173 Failed to set property '%hs' to '%hs' on Dn '%hs': 0x%x.\n
10174 Failed to locate user '%hs'.\n
10175 WARNING: search term '%ws' returns multiple results (should be unique).\n\nThe results follow:\n