#18 [**] Kerberos error type limitations (section 5.1.4)

Shoichi Sakane <[email protected]> Fri, 04 Feb 2005 20:29:41 +0900
Newsgroups gmane.ietf.kink
Message-ID <[email protected]>
> #18 [**] Kerberos error type limitations (section 5.1.4)
> 
>	Why should a sender send only those errors?  I'm mostly asking
>	for an explanation to be given to me or to be added to the document
>	rather than liberalization of the requirement.  (Sam Hartman)

I am not sure why the document describes such limitations.
If we don't have any reason, remove the limitations, and remove the text:

	but the sender SHOULD send only the  following errors:

	    KRB5KRB_AP_ERR_BAD_INTEGRITY
	    KRB5KRB_AP_ERR_TKT_EXPIRED
	    KRB5KRB_AP_ERR_SKEW
	    KRB5KRB_AP_ERR_NOKEY
	    KRB5KRB_AP_ERR_BADKEYVER