Wireshark-users: [Wireshark-users] [kerberos]e-date field is not parsered in krb-erorr packet
From: "Xiaoguang Liu" <syslxg@xxxxxxxxx>
Date: Tue, 30 Jan 2007 20:05:08 +0800
please check the two cap file attached.

there is a e-data at the end of the last frame in both files. there is a NTstatus code is the e-date file. but Wireshark parsered the one in KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN.cap but not "KRB5KDC_ERR_CLIENT_REVOKED for AS.cap". the NTstatus code is very helpful for trouble shooting kerberos issues. So it will be great if this problem can be fixed.

Version 0.99.6-SVN-20621 (SVN Rev 20621) on xp sp2

Attachment: KRB5KDC_ERR_CLIENT_REVOKED for AS.cap
Description: Binary data

Attachment: KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN.cap
Description: Binary data