// Copyright 1997 The Open Group Research Institute.  All rights reserved.

package krb5.lib;

import java.util.Dictionary;
import java.util.Hashtable;

/**
 * Constants and other defined values from RFC 1510
 */
public class Krb5 {

	//Recommended KDC values

    /**
     * Default allowable clock skew
     */
	public static final int DEFAULT_ALLOWABLE_CLOCKSKEW = 5 * 60; //5 minutes
	
	/**
	 * Default minimum lifetime
	 */
	public static final int DEFAULT_MINIMUM_LIFETIME = 5 * 60; //5 minutes
	
	/**
	 * Default maximum renewable lifetime
	 */
	public static final int DEFAULT_MAXIMUM_RENEWABLE_LIFETIME = 7 * 24 * 60 * 60; //1 week
	/**
	 * Default maximum ticket lifetime
	 */
	public static final int DEFAULT_MAXIMUM_TICKET_LIFETIME = 24 * 60 * 60; //1 day
	
	/**
	 * Whether to allow empty address 
	 */
	public static final boolean DEFAULT_EMPTY_ADDRESSES_ALLOWED = true; //XXX not really
	
	/**
	 * Whether forwarding is allowed
	 */
	public static final boolean DEFAULT_FORWARDABLE_ALLOWED = true;
	
	/**
	 * Whether to allow proxy
	 */
	public static final boolean DEFAULT_PROXIABLE_ALLOWED = true;
	
	/**
	 * Whether to allow postdated credentials
	 */
	public static final boolean DEFAULT_POSTDATE_ALLOWED = true;
	
	/**
	 * Whether to allow renewable cerdentials
	 */
	public static final boolean DEFAULT_RENEWABLE_ALLOWED = true;

	//AP_REQ Options

    /**
     * AP Request option - reserved
     */
	public static final int AP_OPTS_RESERVED        = 0;
	
    /**
     * AP Request option - use session key
     */	
	public static final int AP_OPTS_USE_SESSION_KEY = 1;
	
    /**
     * AP Request option - mutual authentication required
     */	
	public static final int AP_OPTS_MUTUAL_REQUIRED = 2;
	
    /**
     * AP Request option - maximum allowable value
     */		
	public static final int AP_OPTS_MAX             = 31;

	//Ticket Flags

    /** 
     * Ticket flag - reserved
     */
	public static final int TKT_OPTS_RESERVED                  = 0;

    /** 
     * Ticket flag - forwardable
     */
	public static final int TKT_OPTS_FORWARDABLE               = 1;

    /** 
     * Ticket flag - forwarded
     */
	public static final int TKT_OPTS_FORWARDED                 = 2;

    /** 
     * Ticket flag - proxiable
     */
	public static final int TKT_OPTS_PROXIABLE                 = 3;

    /** 
     * Ticket flag - proxy
     */
	public static final int TKT_OPTS_PROXY                     = 4;

    /** 
     * Ticket flag - may be postdated
     */
	public static final int TKT_OPTS_MAY_POSTDATE              = 5;

    /** 
     * Ticket flag - postdated
     */
	public static final int TKT_OPTS_POSTDATED                 = 6;

    /** 
     * Ticket flag - invalid
     */
	public static final int TKT_OPTS_INVALID                   = 7;

    /** 
     * Ticket flag - renewable
     */
	public static final int TKT_OPTS_RENEWABLE                 = 8;

    /** 
     * Ticket flag - initial
     */
	public static final int TKT_OPTS_INITIAL                   = 9;

    /** 
     * Ticket flag - pre-authentication
     */
	public static final int TKT_OPTS_PRE_AUTHENT               = 10;

    /** 
     * Ticket flag - hardware authentication
     */
	public static final int TKT_OPTS_HW_AUTHENT                = 11;

    /** 
     * Ticket flag - transited policy checked
     */
	public static final int TKT_OPTS_TRANSITED_POLICY_CHECKED  = 12;

    /** 
     * Ticket flag - OK as delegate
     */
	public static final int TKT_OPTS_OK_AS_DELEGATE            = 13;

    /** 
     * Ticket flag - maximum value
     */
	public static final int TKT_OPTS_MAX                       = 31;

	//KDC Options

    /**
     * KDC options - reserved
     */
	public static final int KDC_OPTS_RESERVED                    = 0;

    /**
     * KDC options - forwardable
     */
	public static final int KDC_OPTS_FORWARDABLE                 = 1;

    /**
     * KDC options - forwarded
     */
	public static final int KDC_OPTS_FORWARDED                   = 2;

    /**
     * KDC options - proxiable
     */
	public static final int KDC_OPTS_PROXIABLE                   = 3;

    /**
     * KDC options - proxy
     */
	public static final int KDC_OPTS_PROXY                       = 4;

    /**
     * KDC options - allow postdate
     */
	public static final int KDC_OPTS_ALLOW_POSTDATE              = 5;

    /**
     * KDC options - postdated
     */
	public static final int KDC_OPTS_POSTDATED                   = 6;

    /**
     * KDC options - unused7
     */
	public static final int KDC_OPTS_UNUSED7                     = 7;

    /**
     * KDC options - renewable
     */
	public static final int KDC_OPTS_RENEWABLE                   = 8;

    /**
     * KDC options - unused9
     */
	public static final int KDC_OPTS_UNUSED9                     = 9;

    /**
     * KDC options - unused10
     */
	public static final int KDC_OPTS_UNUSED10                    = 10;

    /**
     * KDC options - unused11
     */
	public static final int KDC_OPTS_UNUSED11                    = 11;

    /**
     * KDC options - unused12
     */
	public static final int KDC_OPTS_UNUSED12                    = 12;

    /**
     * KDC options - unused13
     */
	public static final int KDC_OPTS_UNUSED13                    = 13;

    /**
     * KDC options - diable transisted checked
     */
	public static final int KDC_OPTS_DISABLE_TRANSISTED_CHECKED  = 26;

    /**
     * KDC options - renewable is ok
     */
	public static final int KDC_OPTS_RENEWABLE_OK                = 27;

    /**
     * KDC options - encrypted key in skey
     */
	public static final int KDC_OPTS_ENC_TKT_IN_SKEY             = 28;

    /**
     * KDC options - renew
     */
	public static final int KDC_OPTS_RENEW                       = 30;

    /**
     * KDC options - validate
     */
	public static final int KDC_OPTS_VALIDATE                    = 31;

    /**
     * KDC options - maximum value
     */
	public static final int KDC_OPTS_MAX                         = 31;

	//Last Request types

    /**
     * Last request type - none
     */
	public static final int LRTYPE_NONE                 = 0;
    
    /**
     * Last request type - time of initial ticket
     */
	public static final int LRTYPE_TIME_OF_INITIAL_TGT  = 1;
    
    /**
     * Last request type - time of initial request
     */
	public static final int LRTYPE_TIME_OF_INITIAL_REQ  = 2;
    
    /**
     * Last request type - time of newest ticket
     */
	public static final int LRTYPE_TIME_OF_NEWEST_TGT   = 3;
    
    /**
     * Last request type - time of last renewal
     */
	public static final int LRTYPE_TIME_OF_LAST_RENEWAL = 4;
    
    /**
     * Last request type - time of last request
     */
	public static final int LRTYPE_TIME_OF_LAST_REQ     = 5;

    /**
     * Last request type - time of password expiration
     */
	public static final int LRTYPE_TIME_OF_PASSWORD_EXP = 6;

	//Host address lengths

    /**
     * Host address length - inet
     */
	public static final int ADDR_LEN_INET      = 4;

    /**
     * Host address length - chaos
     */
	public static final int ADDR_LEN_CHAOS     = 2;

    /**
     * Host address length - osi
     */
	public static final int ADDR_LEN_OSI       = 0; //means variable

    /**
     * Host address length - xns
     */
	public static final int ADDR_LEN_XNS       = 6;

    /**
     * Host address length - appletalk
     */
	public static final int ADDR_LEN_APPLETALK = 3;

    /**
     * Host address length - decnet
     */
	public static final int ADDR_LEN_DECNET    = 2;

	//Host address types

    /**
     * Host address type - Unix
     */
	public static final int ADDRTYPE_UNIX      = 1;  // Unix

    /**
     * Host address type - Internet
     */
	public static final int ADDRTYPE_INET      = 2;  // Internet

    /**
     * Host address type - Arpanet
     */
	public static final int ADDRTYPE_IMPLINK   = 3;  // Arpanet

    /**
     * Host address type - PUP
     */
	public static final int ADDRTYPE_PUP       = 4;  // PUP

    /**
     * Host address type - CHAOS
     */
	public static final int ADDRTYPE_CHAOS     = 5;  // CHAOS

    /**
     * Host address type - XEROX Network Services
     */
	public static final int ADDRTYPE_XNS       = 6;  // XEROX Network Services

    /**
     * Host address type - IPX
     */
	public static final int ADDRTYPE_IPX       = 6;  // IPX

    /**
     * Host address type - OSI
     */
	public static final int ADDRTYPE_OSI       = 7;  // OSI

    /**
     * Host address type - European Computer Manufacturers
     */
	public static final int ADDRTYPE_ECMA      = 8;  // European Computer Manufacturers

    /**
     * Host address type - Datakit
     */
	public static final int ADDRTYPE_DATAKIT   = 9;  // Datakit

    /**
     * Host address type - CCITT
     */
	public static final int ADDRTYPE_CCITT     = 10; // CCITT

    /**
     * Host address type - SNA
     */
	public static final int ADDRTYPE_SNA       = 11; // SNA

    /**
     * Host address type - DECnet
     */
	public static final int ADDRTYPE_DECNET    = 12; // DECnet

    /**
     * Host address type - LAT
     */
	public static final int ADDRTYPE_DLI       = 13; // Direct Data Link Interface

    /**
     * Host address type - local
     */
	public static final int ADDRTYPE_LAT       = 14; // LAT

    /**
     * Host address type - NSC Hyperchannel
     */
	public static final int ADDRTYPE_HYLINK    = 15; // NSC Hyperchannel

    /**
     * Host address type - AppleTalk
     */
	public static final int ADDRTYPE_APPLETALK = 16; // AppleTalk

    /**
     * Host address type - NetBios
     */
	public static final int ADDRTYPE_NETBIOS   = 17; // NetBios

    /**
     * Host address type - VoiceView
     */
	public static final int ADDRTYPE_VOICEVIEW = 18; // VoiceView

    /**
     * Host address type - Firefox
     */
	public static final int ADDRTYPE_FIREFOX   = 19; // Firefox

    /**
     * Host address type - Banyan
     */
	public static final int ADDRTYPE_BAN       = 21; // Banyan

    /**
     * Host address type - ATM
     */
	public static final int ADDRTYPE_ATM       = 22; // ATM

    /**
     * Host address type - Internet Protocol V6
     */
	public static final int ADDRTYPE_INET6     = 23; // Internet Protocol V6

	//IP Transport UDP Port for KDC Messages

    /**
     * Default inet port
     */
	public static final int KDC_INET_DEFAULT_PORT = 88;

	//OSI authentication mechanism OID

    /**
     * OSI authentication mechanism OID
     */
	public static final int[] OSI_AUTH_MECH_TYPE = { /*iso*/ 1, /*org*/ 3,
		/*dod*/ 5, /*internet*/ 1, /*security*/ 5, /*kerberosv5*/ 2 };

    /**
     * Name component separator
     */
	public static final char NAME_COMPONENT_SEPARATOR = '/';
	
	/**
	 * Realm separator
	 */
	public static final char NAME_REALM_SEPARATOR = '@';

	//Protocol constants and associated values

	//Key Types
	/**
	 * Key type - null
	 */
	public static final int KEYTYPE_NULL = 0;
	
	/**
	 * Key type - DES
	 */
	public static final int KEYTYPE_DES  = 1;

	//-------------------------------------------+-----------+----------+----------------+---------------
	//                      Encryption type      |etype value|block size|minimum pad size|confounder size
	//-------------------------------------------+-----------+----------+----------------+---------------
	
	/**
	 * Encryption type - null
	 */
	public static final int ETYPE_NULL          = 0;       // 1          0                0
	
	/**
	 * Encryption type - DES CBC CRC
	 */
	public static final int ETYPE_DES_CBC_CRC   = 1;       // 8          4                8
	
	/**
	 * Encryption type - DES CBC MD4
	 */
	public static final int ETYPE_DES_CBC_MD4   = 2;       // 8          0                8
	
	/**
	 * Encryption type - DES CBC MD5 
	 */
	public static final int ETYPE_DES_CBC_MD5   = 3;       // 8          0                8
	
	/**
	 * Encryption type - DES3 CBC MD5
	 */
	public static final int ETYPE_DES3_CBC_MD5  = 5;       // 8          0                8
	
	/**
	 * Encryption type - DES3 CBC SHA1
	 */
	public static final int ETYPE_DES3_CBC_SHA1 = 7;       // 8          0                8
	
	/**
	 * Encryption type - SA with SHA1 CMS oid
	 */
	public static final int ETYPE_DSA_WITH_SHA1_CMS_OID = 9;
	
	/**
	 * Encryption type - MD5 with RSA encryption CMS oid
	 */
	public static final int ETYPE_MD5_WITH_RSA_ENCRYPTION_CMS_OID = 10;
	
	/**
	 * Encryption type - SHA1 with RSA encryption CMS oid
	 */
	public static final int ETYPE_SHA1_WITH_RSA_ENCRYPTION_CMS_OID = 11;
	
	/**
	 * Encryption type - RC2 CBC environment oid
	 */
	public static final int ETYPE_RC2_CBC_ENV_OID = 12;
	
	/**
	 * Encryption type - RSA encryption environment oid
	 */
	public static final int ETYPE_RSA_ENCRYPTION_ENV_OID = 13;
	
	/**
	 * Encryption type - RSA ES OAEP environment oid
	 */
	public static final int ETYPE_RSA_ES_OAEP_ENV_OID = 14;
	
	/**
	 * Encryption type - DES EDE3 CBC environment oid
	 */
	public static final int ETYPE_DES_EDE3_CBC_ENV_OID = 15;
	//XXX public static final int ETYPE_DES3KD_CBC_SHA1 = xx;    // 8          0                8
	
	/**
	 * Encryption type - PK cross
	 */
	public static final int ETYPE_PK_CROSS = 48;

	//------------------------------------------------+-------------------+-------------
	//                      Checksum type             |sumtype value      |checksum size
	//------------------------------------------------+-------------------+-------------
	
	/**
	 * Checksum type - null
	 */
	public static final int CKSUMTYPE_NULL           = 0;               // 0
	
	/**
	 * Checksum type - CRC32
	 */
	public static final int CKSUMTYPE_CRC32          = 1;               // 4
	
	/**
	 * Checksum type - RSA MD4
	 */
	public static final int CKSUMTYPE_RSA_MD4        = 2;               // 16
	
	/**
	 * Checksum type - RSA MD4 DES
	 */
	public static final int CKSUMTYPE_RSA_MD4_DES    = 3;               // 24
	
	/**
	 * Checksum type - DES MAC
	 */
	public static final int CKSUMTYPE_DES_MAC        = 4;               // 16
	
	/**
	 * Checksum type - DES MAC K
	 */
	public static final int CKSUMTYPE_DES_MAC_K      = 5;               // 8
	
	/**
	 * Checksum type - RSA MD4 DES K
	 */
	public static final int CKSUMTYPE_RSA_MD4_DES_K  = 6;               // 16
	
	/**
	 * Checksum type - RSA MD5
	 */
	public static final int CKSUMTYPE_RSA_MD5        = 7;               // 16
	
	/**
	 * Checksum type - RSA MD5 DES
	 */
	public static final int CKSUMTYPE_RSA_MD5_DES    = 8;               // 24
	
	/**
	 * Checksum type - RSA MD5 DES3
	 */
	public static final int CKSUMTYPE_RSA_MD5_DES3   = 9;               // 24
	
	/**
	 * Checksum type - HMAC SHA1 DES3
	 */
	public static final int CKSUMTYPE_HMAC_SHA1_DES3 = 12;              // 20

	//------------------------------------------------+-----------------
	//                      padata type               |padata-type value
	//------------------------------------------------+-----------------
	
	/**
	 * padata type - TGS Request
	 */
	public static final int PA_TGS_REQ               = 1;
	
	/**
	 * padata type - Enc timestamp
	 */
	public static final int PA_ENC_TIMESTAMP         = 2;
	
	/**
	 * padata type - password salt
	 */
	public static final int PA_PW_SALT               = 3;
	
	/**
	 * padata type - enc unix time
	 */
	public static final int PA_ENC_UNIX_TIME         = 5;
	
	/**
	 * padata type - sandia secureid
	 */
	public static final int PA_SANDIA_SECUREID       = 6;
	
	/**
	 * padata type - sesame
	 */
	public static final int PA_SESAME                = 7;
	
	/**
	 * padata type - OSF DCE
	 */
	public static final int PA_OSF_DCE               = 8;
	
	/**
	 * padata type - cybersafe secureid
	 */
	public static final int PA_CYBERSAFE_SECUREID    = 9;
	
	/**
	 * padata type - ASF3 salt
	 */
	public static final int PA_ASF3_SALT             = 10;
	
	/**
	 * padata type - encryption info
	 */
	public static final int PA_ETYPE_INFO            = 11;

	/**
	 * padata type - SAM challenge
	 */
	public static final int SAM_CHALLENGE            = 12;
	
	/**
	 * padata type - SAM response
	 */
	public static final int SAM_RESPONSE             = 13;
	
	/**
	 * padata type - PK as request
	 */
	public static final int PA_PK_AS_REQ             = 14;
	
	/**
	 * padata type - PK as response
	 */
	public static final int PA_PK_AS_REP             = 15;
	
	/**
	 * padata type - use specified key version
	 */
	public static final int PA_USE_SPECIFIED_KVNO    = 20;
	
	/**
	 * padata type - SAM redirect
	 */
	public static final int SAM_REDIRECT             = 21;
	
	/**
	 * padata type - Get from typed data
	 */
	public static final int PA_GET_FROM_TYPED_DATA   = 22;

	//---------------------------------------------------+-------------
	//typed data                                         |td-type value
	//---------------------------------------------------+-------------
	
	/**
	 * Typed data - PA data
	 */
	public static final int TD_PADATA                   = 22;
	
	/**
	 * Typed data - Pkinit cms certificates
	 */
	public static final int TD_PKINIT_CMS_CERTIFICATES  = 101;
	
	/**
	 * Typed data - KRB principal
	 */
	public static final int TD_KRB_PRINCIPAL            = 102;
	
	/**
	 * Typed data - KRB realm
	 */
	public static final int TD_KRB_REALM                = 103;
	
	/**
	 * Typed data - trusted certifiers
	 */
	public static final int TD_TRUSTED_CERTIFIERS       = 104;
	
	/**
	 * Typed data - certificate index
	 */
	public static final int TD_CERTIFICATE_INDEX        = 105;

	//----------------------------------------------------------+-------------
	//authorization data type                                   |ad-type value
	//----------------------------------------------------------+-------------

    /**
     * Authorization data type - if relevant
     */
	public static final int AD_IF_RELEVANT                     = 1;

    /**
     * Authorization data type - intended for server
     */
	public static final int AD_INTENDED_FOR_SERVER             = 2;

    /**
     * Authorization data type - intented for application class
     */
	public static final int AD_INTENDED_FOR_APPLICATION_CLASS  = 3;

    /**
     * Authorization data type - kdc issued
     */
	public static final int AD_KDC_ISSUED                      = 4;

    /**
     * Authorization data type - or
     */
	public static final int AD_OR                              = 5;

    /**
     * Authorization data type - manditory ticket extensions
     */
	public static final int AD_MANDITORY_TICKET_EXTENSIONS     = 6;

    /**
     * Authorization data type - in ticket extensions
     */
	public static final int AD_IN_TICKET_EXTENSIONS            = 7;
	//reserved values                                            8-63

    /**
     * Authorization data type - OSF DCE
     */
	public static final int OSF_DCE                            = 64;

    /**
     * Authorization data type - sesame
     */
	public static final int SESAME                             = 65;

	//-----------------------------------------------+-------------
	//ticket extensions type                         |te-type value
	//-----------------------------------------------+-------------

	/**
	 * Ticket extensions type - null
	 */
	public static final int TE_TYPE_NULL            = 0;

	/**
	 * Ticket extensions type - external data
	 */
	public static final int TE_TYPE_EXTERNAL_ADATA  = 1;

	/**
	 * Ticket extensions type - PK cross client
	 */
	public static final int TE_TYPE_PKCROSS_CLIENT  = 3;

	/**
	 * Ticket extensions type - cybersafe extensions
	 */
	public static final int TE_TYPE_CYBERSAFE_EXT   = 4;

	//----------------------------------------------+-----------------
	//alternate authentication type                 |method-type value
	//----------------------------------------------+-----------------
	//                      reserved values          0-63
	/**
	 * Alternate authentication type - challenge response
	 */
	public static final int ATT_CHALLENGE_RESPONSE = 64;

	//--------------------------------------------+-------------
	//transited encoding type                     |tr-type value
	//--------------------------------------------+-------------
	/**
	 * Transited encoding type - Domain x500 compress
	 */
	public static final int DOMAIN_X500_COMPRESS = 1;
	//                      reserved values        all others

	//----------------------------+-------+-----------------------------------------
	//                      Label |Value  |Meaning
	//----------------------------+-------+-----------------------------------------
	/**
	 * Kerberos protocol version number
	 */
	public static final int PVNO = 5;   // current Kerberos protocol version number
	
	/**
	 * Authenticator version number
	 */
	public static final int AUTHNETICATOR_VNO = 5;   // current authenticator version number

    /**
     * Ticket version number
     */
	public static final int TICKET_VNO = 5;   // current ticket version number

	//message types

	//XXX there are several message sub-components not included here
	
	/**
	 * Message types - initial authentication request
	 */
	public static final int KRB_AS_REQ =  10;     //Request for initial authentication
	
	/**
	 * Message types - initial authentication response
	 */
	public static final int KRB_AS_REP =  11;     //Response to KRB_AS_REQ request
	
	/**
	 * Message types - request for authentication based on TGT
	 */
	public static final int KRB_TGS_REQ = 12;     //Request for authentication based on TGT
	
	/**
	 * Message types - response to authentication based on TGT
	 */
	public static final int KRB_TGS_REP = 13;     //Response to KRB_TGS_REQ request
	
	/**
	 * Message types - application request
	 */
	public static final int KRB_AP_REQ =  14;     //application request to server
	
	/**
	 * Message types - application response 
	 */
	public static final int KRB_AP_REP =  15;     //Response to KRB_AP_REQ_MUTUAL
	
	/**
	 * Message types - safe (checksummed) application message
	 */
	public static final int KRB_SAFE =    20;     //Safe (checksummed) application message
	
	/**
	 * Message types - private (encrypted) application message
	 */
	public static final int KRB_PRIV =    21;     //Private (encrypted) application message
	
	/**
	 * Message types - private (encrypted) message to forward credentials
	 */
	public static final int KRB_CRED =    22;     //Private (encrypted) message to forward credentials
	
	/**
	 * Message types - error response
	 */
	public static final int KRB_ERROR =   30;     //Error response

	//message component types

    /**
     * Message component type - ticket
     */
	public static final int KRB_TKT               = 1;  //Ticket

    /**
     * Message component type - authenticator
     */
	public static final int KRB_AUTHENTICATOR     = 2;  //Authenticator

    /**
     * Message component type - encrypted ticket part
     */
	public static final int KRB_ENC_TKT_PART      = 3;  //Encrypted ticket part

    /**
     * Message component type - encrypted initial authentication part
     */
	public static final int KRB_ENC_AS_REP_PART   = 25; //Encrypted initial authentication part

    /**
     * Message component type - encrypted TGS request part
     */
	public static final int KRB_ENC_TGS_REP_PART  = 26; //Encrypted TGS request part

    /**
     * Message component type - encrypted application request part
     */
	public static final int KRB_ENC_AP_REP_PART   = 27; //Encrypted application request part

    /**
     * Message component type - encrypted application message part
     */
	public static final int KRB_ENC_KRB_PRIV_PART = 28; //Encrypted application message part

    /**
     * Message component type - encrypted credentials forward part
     */
	public static final int KRB_ENC_KRB_CRED_PART = 29; //Encrypted credentials forward part


	//name types

    /**
     * Name type - name type not known
     */
	public static final int KRB_NT_UNKNOWN         = 0;   //Name type not known

    /**
     * Name type - just the name of the principal as in DCE, or for users
     */
    public static final int KRB_NT_PRINCIPAL       = 1;   //Just the name of the principal as in DCE, or for users

    /**
     * Name type - service and other unique instance (krbtgt)
     */
	public static final int KRB_NT_SRV_INST        = 2;   //Service and other unique instance (krbtgt)

    /**
     * Name type - service with host name as instance (telnet, rcommands)
     */
	public static final int KRB_NT_SRV_HST         = 3;   //Service with host name as instance (telnet, rcommands)

    /**
     * Name type - service with host as remaining components
     */
	public static final int KRB_NT_SRV_XHST        = 4;   //Service with host as remaining components

    /**
     * Name type - unique id
     */
	public static final int KRB_NT_UID             = 5;   //Unique ID

    /**
     * Name type - nt x500 principal
     */
	public static final int KRB_NT_X500_PRINCIPAL  = 6;   //Encoded X.509 Distinguished name [RFC 2253]

	//TGS Name
    /**
     * Default server name
     */
	public static final String TGS_DEFAULT_SRV_NAME = "krbtgt";
	
	/**
	 * Default NT
	 */
	public static final int TGS_DEFAULT_NT = KRB_NT_SRV_INST;
	
	//keytab versions
	
	/**
	 * Keytab version - DCE compatible
	 */
	public static final int KT_VNO_1 = 0x0501;   //DCE compatible
	
	/**
	 * MIT Kerb5 beta compatible
	 */
	public static final int KT_VNO_2 = 0x0502;   //MIT Kerb5 beta compatible

	//error codes
	
    /**
     * Error - No error
     */
	public static final int KDC_ERR_NONE                 =  0;   //No error
	
    /**
     * Error - Client's entry in database expired
     */
	public static final int KDC_ERR_NAME_EXP             =  1;   //Client's entry in database expired
	
    /**
     * Error - Server's entry in database has expired
     */
	public static final int KDC_ERR_SERVICE_EXP          =  2;   //Server's entry in database has expired
	
    /**
     * Error - Requested protocol version number not supported
     */
	public static final int KDC_ERR_BAD_PVNO             =  3;   //Requested protocol version number not supported
	
    /**
     * Error - Client's key encrypted in old master key
     */
	public static final int KDC_ERR_C_OLD_MAST_KVNO      =  4;   //Client's key encrypted in old master key
	
    /**
     * Error - Server's key encrypted in old master key
     */
	public static final int KDC_ERR_S_OLD_MAST_KVNO      =  5;   //Server's key encrypted in old master key
	
    /**
     * Error - Client not found in Kerberos database
     */
	public static final int KDC_ERR_C_PRINCIPAL_UNKNOWN  =  6;   //Client not found in Kerberos database
	
    /**
     * Error - Server not found in Kerberos database
     */
	public static final int KDC_ERR_S_PRINCIPAL_UNKNOWN  =  7;   //Server not found in Kerberos database
	
    /**
     * Error - Multiple principal entries in database
     */
	public static final int KDC_ERR_PRINCIPAL_NOT_UNIQUE =  8;   //Multiple principal entries in database
	
    /**
     * Error - The client or server has a null key
     */
	public static final int KDC_ERR_NULL_KEY             =  9;   //The client or server has a null key
	
    /**
     * Error - Ticket not eligible for postdating
     */
	public static final int KDC_ERR_CANNOT_POSTDATE      = 10;   //Ticket not eligible for postdating
	
    /**
     * Error - Requested start time is later than end time
     */
	public static final int KDC_ERR_NEVER_VALID          = 11;   //Requested start time is later than end time
	
    /**
     * Error - KDC policy rejects request
     */
	public static final int KDC_ERR_POLICY               = 12;   //KDC policy rejects request

    /**
     * Error - KDC cannot accommodate requested option
     */
	public static final int KDC_ERR_BADOPTION            = 13;   //KDC cannot accommodate requested option
	
    /**
     * Error - KDC has no support for encryption type
     */
	public static final int KDC_ERR_ETYPE_NOSUPP         = 14;   //KDC has no support for encryption type
	
    /**
     * Error - KDC has no support for checksum type
     */
	public static final int KDC_ERR_SUMTYPE_NOSUPP       = 15;   //KDC has no support for checksum type
	
    /**
     * Error - KDC has no support for padata type
     */
	public static final int KDC_ERR_PADATA_TYPE_NOSUPP   = 16;   //KDC has no support for padata type
	
    /**
     * Error - KDC has no support for transited type
     */
	public static final int KDC_ERR_TRTYPE_NOSUPP        = 17;   //KDC has no support for transited type
	
    /**
     * Error - Clients credentials have been revoked
     */
	public static final int KDC_ERR_CLIENT_REVOKED       = 18;   //Clients credentials have been revoked
	
    /**
     * Error - Credentials for server have been revoked
     */
	public static final int KDC_ERR_SERVICE_REVOKED      = 19;   //Credentials for server have been revoked
	
    /**
     * Error - TGT has been revoked
     */
	public static final int KDC_ERR_TGT_REVOKED          = 20;   //TGT has been revoked
	
    /**
     * Error - Client not yet valid - try again later
     */
	public static final int KDC_ERR_CLIENT_NOTYET        = 21;   //Client not yet valid - try again later
	
    /**
     * Error - Server not yet valid - try again later
     */
	public static final int KDC_ERR_SERVICE_NOTYET       = 22;   //Server not yet valid - try again later
	
    /**
     * Error - Password has expired - change password to reset
     */
	public static final int KDC_ERR_KEY_EXPIRED          = 23;   //Password has expired - change password to reset
	
    /**
     * Error - Pre-authentication information was invalid
     */
	public static final int KDC_ERR_PREAUTH_FAILED       = 24;   //Pre-authentication information was invalid
	
    /**
     * Error - Additional pre-authentication required
     */
	public static final int KDC_ERR_PREAUTH_REQUIRED     = 25;   //Additional pre-authentication required
	
    /**
     * Error - Requested server and ticket don't match
     */
	public static final int KDC_ERR_SERVER_NOMATCH       = 26;   //Requested server and ticket don't match
	
    /**
     * Error - Server valid for user2user only
     */
	public static final int KDC_ERR_MUST_USE_USER2USER   = 27;   //Server valid for user2user only
	
    /**
     * Error - KDC Policy rejects transited path
     */
	public static final int KDC_ERR_PATH_NOT_ACCEPTED    = 28;   //KDC Policy rejects transited path
	
    /**
     * Error - A service is not available
     */
	public static final int KDC_ERR_SVC_UNAVAILABLE      = 29;   //A service is not available
	
    /**
     * Error - Integrity check on decrypted field failed
     */
	public static final int KRB_AP_ERR_BAD_INTEGRITY     = 31;   //Integrity check on decrypted field failed
	
    /**
     * Error - Ticket expired
     */
	public static final int KRB_AP_ERR_TKT_EXPIRED       = 32;   //Ticket expired
	
    /**
     * Error - Ticket not yet valid
     */
	public static final int KRB_AP_ERR_TKT_NYV           = 33;   //Ticket not yet valid
	
    /**
     * Error - Request is a replay
     */
	public static final int KRB_AP_ERR_REPEAT            = 34;   //Request is a replay
	
    /**
     * Error - The ticket isn't for us
     */
	public static final int KRB_AP_ERR_NOT_US            = 35;   //The ticket isn't for us
	
    /**
     * Error - Ticket and authenticator don't match
     */
	public static final int KRB_AP_ERR_BADMATCH          = 36;   //Ticket and authenticator don't match
	
    /**
     * Error - Clock skew too great
     */
	public static final int KRB_AP_ERR_SKEW              = 37;   //Clock skew too great
	
    /**
     * Error - Incorrect net address
     */
	public static final int KRB_AP_ERR_BADADDR           = 38;   //Incorrect net address
	
    /**
     * Error - Protocol version mismatch
     */
	public static final int KRB_AP_ERR_BADVERSION        = 39;   //Protocol version mismatch
	
    /**
     * Error - Invalid msg type
     */
	public static final int KRB_AP_ERR_MSG_TYPE          = 40;   //Invalid msg type
	
    /**
     * Error - Message stream modified
     */
	public static final int KRB_AP_ERR_MODIFIED          = 41;   //Message stream modified
	
    /**
     * Error - Message out of order
     */
	public static final int KRB_AP_ERR_BADORDER          = 42;   //Message out of order
	
    /**
     * Error - Specified version of key is not available
     */
	public static final int KRB_AP_ERR_BADKEYVER         = 44;   //Specified version of key is not available
	
    /**
     * Error - Service key not available
     */
	public static final int KRB_AP_ERR_NOKEY             = 45;   //Service key not available
	
    /**
     * Error - Mutual authentication failed
     */
	public static final int KRB_AP_ERR_MUT_FAIL          = 46;   //Mutual authentication failed
	
    /**
     * Error - Incorrect message direction
     */
	public static final int KRB_AP_ERR_BADDIRECTION      = 47;   //Incorrect message direction
	
    /**
     * Error - Alternative authentication method required
     */
	public static final int KRB_AP_ERR_METHOD            = 48;   //Alternative authentication method required
	
    /**
     * Error - Incorrect sequence number in message
     */
	public static final int KRB_AP_ERR_BADSEQ            = 49;   //Incorrect sequence number in message
	
    /**
     * Error - Inappropriate type of checksum in message
     */
	public static final int KRB_AP_ERR_INAPP_CKSUM       = 50;   //Inappropriate type of checksum in message
	
    /**
     * Error - Generic error (description in e-text)
     */
	public static final int KRB_ERR_GENERIC              = 60;   //Generic error (description in e-text)
	
    /**
     * Error - Field is too long for this implementation
     */
	public static final int KRB_ERR_FIELD_TOOLONG        = 61;   //Field is too long for this implementation
	
    /**
     * Error - Client is not trusted
     */
	public static final int KRB_ERR_CLIENT_NOT_TRUSTED            = 62;   //Client is not trusted
	
    /**
     * Error - KDC is not trusted
     */
	public static final int KRB_ERR_KDC_NOT_TRUSTED               = 63;   //KDC is not trusted
	
    /**
     * Error - Signature is invalid
     */
	public static final int KRB_ERR_INVALID_SIG                   = 64;   //Signature is invalid
	
    /**
     * Error - Key too weak
     */
	public static final int KRB_ERR_KEY_TOO_WEAK                  = 65;   //Key too weak
	
    /**
     * Error - Certificates do not match
     */
	public static final int KRB_ERR_CERTIFICATE_MISMATCH          = 66;   //Certificates do not match
	
    /**
     * Error - No tgt for user-to-user authentication
     */
	public static final int KRB_AP_ERR_NO_TGT                     = 67;   //No tgt for user-to-user authentication
	
    /**
     * Error - Wrong realm
     */
	public static final int KRB_ERR_WRONG_REALM                   = 68;   //Wrong realm
	
    /**
     * Error - User-to-user authentication required
     */
	public static final int KRB_AP_ERR_USER_TO_USER_REQUIRED      = 69;   //User-to-user authentication required
	
    /**
     * Error - Can't verify certificate
     */
	public static final int KRB_ERR_CANT_VERIFY_CERTIFICATE       = 70;   //Can't verify certificate
	
    /**
     * Error - Invalid certificate
     */
	public static final int KRB_ERR_INVALID_CERTIFICATE           = 71;   //Invalid certificate
	
    /**
     * Error - Revoked certificate
     */
	public static final int KRB_ERR_REVOKED_CERTIFICATE           = 72;   //Revoked certificate
	
    /**
     * Error - Revocation status unknown
     */
	public static final int KRB_ERR_REVOCATION_STATUS_UNKNOWN     = 73;   //Revocation status unknown
	
    /**
     * Error - Revocation status unavailable
     */
	public static final int KRB_ERR_REVOCATION_STATUS_UNAVAILABLE = 74;   //Revocation status unavailable
	
    /**
     * Error - Client names do not match
     */
	public static final int KRB_ERR_CLIENT_NAME_MISMATCH          = 75;   //Client names do not match
	
    /**
     * Error - KDC names do not match
     */
	public static final int KRB_ERR_KDC_NAME_MISMATCH             = 76;   //KDC names do not match

	// error codes specific to this implementation

    /**
     * Error - Invalid argument
     */
	public static final int API_INVALID_ARG               = 400;  //Invalid argument

    /**
     * Error - BitString size does not match input byte array
     */
	public static final int BITSTRING_SIZE_INVALID        = 500;  //BitString size does not match input byte array

    /**
     * Error - BitString bit index does not fall within size
     */
	public static final int BITSTRING_INDEX_OUT_OF_BOUNDS = 501;  //BitString bit index does not fall within size

    /**
     * Error - BitString length is wrong for the expected type
     */
	public static final int BITSTRING_BAD_LENGTH          = 502;  //BitString length is wrong for the expected type

    /**
     * Error - Illegal character in realm name; one of: '/', ':'
     */
	public static final int REALM_ILLCHAR                 = 600;  //Illegal character in realm name; one of: '/', ':', '\0'

    /**
     * Error - Null realm name
     */
	public static final int REALM_NULL                    = 601;  //Null realm name
	
    /**
     * Error - Credentials cache not found
     */
	public static final int CCACHE_NOT_FOUND              = 700;  //Credentials cache not found
	
    /**
     * Error - Invalid credentials cache type
     */
    public static final int CCACHE_INVALID_TYPE           = 701;  //Invalid credentials cache type
		
    /**
     * Error - Keytab file not found
     */
    public static final int KT_FILE_NOT_FOUND             = 800;  //Keytab file not found
	
    /**
     * Error - Keytab file corrupt
     */
    public static final int KT_FILE_CORRUPT               = 801;  //Keytab file corrupt
	
    /**
     * Error - Keytab file version unsupported
     */
	public static final int KT_FILE_VERSION_UNSUPPORTED   = 802;  //Keytab file version unsupported
	
    /**
     * Error - Keytab file entry not found
     */
	public static final int KT_FILE_ENTRY_NOT_FOUND       = 803;  //Keytab file entry not found
	
    /**
     * Error - Input not in GeneralizedTime format
     */
	public static final int ASN1_BAD_TIMEFORMAT           = 900;  //Input not in GeneralizedTime format
	
    /**
     * Error - Structure is missing a required field
     */
	public static final int ASN1_MISSING_FIELD            = 901;  //Structure is missing a required field
	
    /**
     * Error - Unexpected field number
     */
	public static final int ASN1_MISPLACED_FIELD          = 902;  //Unexpected field number
	
    /**
     * Error - Type numbers are inconsistent
     */
	public static final int ASN1_TYPE_MISMATCH            = 903;  //Type numbers are inconsistent
	
    /**
     * Error - Value too large
     */
	public static final int ASN1_OVERFLOW                 = 904;  //Value too large
	
    /**
     * Error - Encoding ended unexpectedly
     */
	public static final int ASN1_OVERRUN                  = 905;  //Encoding ended unexpectedly
	
    /**
     * Error - Identifier doesn't match expected value
     */
	public static final int ASN1_BAD_ID                   = 906;  //Identifier doesn't match expected value
	
    /**
     * Error - Length doesn't match expected value
     */
	public static final int ASN1_BAD_LENGTH               = 907;  //Length doesn't match expected value
	
    /**
     * Error - Badly-formatted encoding
     */
	public static final int ASN1_BAD_FORMAT               = 908;  //Badly-formatted encoding
	
    /**
     * Error - Parse error
     */
	public static final int ASN1_PARSE_ERROR              = 909;  //Parse error
	
    /**
     * Error - Bad class number
     */
	public static final int ASN1_BAD_CLASS                = 910;  //Bad class number
	
    /**
     * Error - Bad type number
     */
	public static final int ASN1_BAD_TYPE                 = 911;  //Bad type number
	
    /**
     * Error - Bad tag number
     */
	public static final int ASN1_BAD_TAG                  = 912;  //Bad tag number
	
    /**
     * Error - Unsupported ASN.1 type encountered
     */
	public static final int ASN1_UNSUPPORTED_TYPE         = 913;  //Unsupported ASN.1 type encountered
	
    /**
     * Error - Encoding failed due to invalid parameter(s)
     */
	public static final int ASN1_CANNOT_ENCODE            = 914;  //Encoding failed due to invalid parameter(s)
	
    /**
     * Error - Config file not found
     */
	public static final int CONF_FILE_NOT_FOUND           = 1000;  //Config file not found
	
    /**
     * Error - Config file read failed
     */
	public static final int CONF_FILE_READ_FAILED         = 1001;  //Config file read failed
	
    /**
     * Error - Config file parse failure
     */
	public static final int CONF_FILE_PARSE_FAILURE       = 1002;  //Config file parse failure

    /**
     * Error message list
     */
	static Dictionary errMsgList;

	static {
		errMsgList = new Hashtable();
		errMsgList.put(new Integer(KDC_ERR_NONE), "No error");
		errMsgList.put(new Integer(KDC_ERR_NAME_EXP), "Client's entry in database expired");
		errMsgList.put(new Integer(KDC_ERR_SERVICE_EXP), "Server's entry in database has expired");
		errMsgList.put(new Integer(KDC_ERR_BAD_PVNO), "Requested protocol version number not supported");
		errMsgList.put(new Integer(KDC_ERR_C_OLD_MAST_KVNO), "Client's key encrypted in old master key");
		errMsgList.put(new Integer(KDC_ERR_S_OLD_MAST_KVNO), "Server's key encrypted in old master key");
		errMsgList.put(new Integer(KDC_ERR_C_PRINCIPAL_UNKNOWN), "Client not found in Kerberos database");
		errMsgList.put(new Integer(KDC_ERR_S_PRINCIPAL_UNKNOWN), "Server not found in Kerberos database");
		errMsgList.put(new Integer(KDC_ERR_PRINCIPAL_NOT_UNIQUE), "Multiple principal entries in database");
		errMsgList.put(new Integer(KDC_ERR_NULL_KEY), "The client or server has a null key");
		errMsgList.put(new Integer(KDC_ERR_CANNOT_POSTDATE), "Ticket not eligible for postdating");
		errMsgList.put(new Integer(KDC_ERR_NEVER_VALID), "Requested start time is later than end time");
		errMsgList.put(new Integer(KDC_ERR_POLICY), "KDC policy rejects request");
		errMsgList.put(new Integer(KDC_ERR_BADOPTION), "KDC cannot accommodate requested option");
		errMsgList.put(new Integer(KDC_ERR_ETYPE_NOSUPP), "KDC has no support for encryption type");
		errMsgList.put(new Integer(KDC_ERR_SUMTYPE_NOSUPP), "KDC has no support for checksum type");
		errMsgList.put(new Integer(KDC_ERR_PADATA_TYPE_NOSUPP), "KDC has no support for padata type");
		errMsgList.put(new Integer(KDC_ERR_TRTYPE_NOSUPP), "KDC has no support for transited type");
		errMsgList.put(new Integer(KDC_ERR_CLIENT_REVOKED), "Clients credentials have been revoked");
		errMsgList.put(new Integer(KDC_ERR_SERVICE_REVOKED), "Credentials for server have been revoked");
		errMsgList.put(new Integer(KDC_ERR_TGT_REVOKED), "TGT has been revoked");
		errMsgList.put(new Integer(KDC_ERR_CLIENT_NOTYET), "Client not yet valid - try again later");
		errMsgList.put(new Integer(KDC_ERR_SERVICE_NOTYET), "Server not yet valid - try again later");
		errMsgList.put(new Integer(KDC_ERR_KEY_EXPIRED), "Password has expired - change password to reset");
		errMsgList.put(new Integer(KDC_ERR_PREAUTH_FAILED), "Pre-authentication information was invalid");
		errMsgList.put(new Integer(KDC_ERR_PREAUTH_REQUIRED), "Additional pre-authentication required");
		errMsgList.put(new Integer(KDC_ERR_SERVER_NOMATCH), "Requested server and ticket don't match");
		errMsgList.put(new Integer(KDC_ERR_MUST_USE_USER2USER), "Server valid for user2user only");
		errMsgList.put(new Integer(KDC_ERR_PATH_NOT_ACCEPTED), "KDC Policy rejects transited path");
		errMsgList.put(new Integer(KDC_ERR_SVC_UNAVAILABLE), "A service is not available");
		errMsgList.put(new Integer(KRB_AP_ERR_BAD_INTEGRITY), "Integrity check on decrypted field failed");
		errMsgList.put(new Integer(KRB_AP_ERR_TKT_EXPIRED), "Ticket expired");
		errMsgList.put(new Integer(KRB_AP_ERR_TKT_NYV), "Ticket not yet valid");
		errMsgList.put(new Integer(KRB_AP_ERR_REPEAT), "Request is a replay");
		errMsgList.put(new Integer(KRB_AP_ERR_NOT_US), "The ticket isn't for us");
		errMsgList.put(new Integer(KRB_AP_ERR_BADMATCH), "Ticket and authenticator don't match");
		errMsgList.put(new Integer(KRB_AP_ERR_SKEW), "Clock skew too great");
		errMsgList.put(new Integer(KRB_AP_ERR_BADADDR), "Incorrect net address");
		errMsgList.put(new Integer(KRB_AP_ERR_BADVERSION), "Protocol version mismatch");
		errMsgList.put(new Integer(KRB_AP_ERR_MSG_TYPE), "Invalid msg type");
		errMsgList.put(new Integer(KRB_AP_ERR_MODIFIED), "Message stream modified");
		errMsgList.put(new Integer(KRB_AP_ERR_BADORDER), "Message out of order");
		errMsgList.put(new Integer(KRB_AP_ERR_BADKEYVER), "Specified version of key is not available");
		errMsgList.put(new Integer(KRB_AP_ERR_NOKEY), "Service key not available");
		errMsgList.put(new Integer(KRB_AP_ERR_MUT_FAIL), "Mutual authentication failed");
		errMsgList.put(new Integer(KRB_AP_ERR_BADDIRECTION), "Incorrect message direction");
		errMsgList.put(new Integer(KRB_AP_ERR_METHOD), "Alternative authentication method required");
		errMsgList.put(new Integer(KRB_AP_ERR_BADSEQ), "Incorrect sequence number in message");
		errMsgList.put(new Integer(KRB_AP_ERR_INAPP_CKSUM), "Inappropriate type of checksum in message");
		errMsgList.put(new Integer(KRB_ERR_GENERIC), "Generic error (description in e-text)");
		errMsgList.put(new Integer(KRB_ERR_FIELD_TOOLONG), "Field is too long for this implementation");
		errMsgList.put(new Integer(KRB_ERR_CLIENT_NOT_TRUSTED), "Client is not trusted");
		errMsgList.put(new Integer(KRB_ERR_KDC_NOT_TRUSTED), "KDC is not trusted");
		errMsgList.put(new Integer(KRB_ERR_INVALID_SIG), "Signature is invalid");
		errMsgList.put(new Integer(KRB_ERR_KEY_TOO_WEAK), "Key too weak");
		errMsgList.put(new Integer(KRB_ERR_CERTIFICATE_MISMATCH), "Certificates do not match");
		errMsgList.put(new Integer(KRB_AP_ERR_NO_TGT), "No tgt for user-to-user authentication");
		errMsgList.put(new Integer(KRB_ERR_WRONG_REALM), "Wrong realm");
		errMsgList.put(new Integer(KRB_AP_ERR_USER_TO_USER_REQUIRED), "User-to-user authentication required");
		errMsgList.put(new Integer(KRB_ERR_CANT_VERIFY_CERTIFICATE), "Can't verify certificate");
		errMsgList.put(new Integer(KRB_ERR_INVALID_CERTIFICATE), "Invalid certificate");
		errMsgList.put(new Integer(KRB_ERR_REVOKED_CERTIFICATE), "Revoked certificate");
		errMsgList.put(new Integer(KRB_ERR_REVOCATION_STATUS_UNKNOWN), "Revocation status unknown");
		errMsgList.put(new Integer(KRB_ERR_REVOCATION_STATUS_UNAVAILABLE), "Revocation status unavailable");
		errMsgList.put(new Integer(KRB_ERR_CLIENT_NAME_MISMATCH), "Client names do not match");
		errMsgList.put(new Integer(KRB_ERR_KDC_NAME_MISMATCH), "KDC names do not match");

		// error messages specific to this implementation

		errMsgList.put(new Integer(API_INVALID_ARG), "Invalid argument");

		errMsgList.put(new Integer(BITSTRING_SIZE_INVALID), "BitString size does not match input byte array");
		errMsgList.put(new Integer(BITSTRING_INDEX_OUT_OF_BOUNDS), "BitString bit index does not fall within size");
		errMsgList.put(new Integer(BITSTRING_BAD_LENGTH), "BitString length is wrong for the expected type");

		errMsgList.put(new Integer(REALM_ILLCHAR), "Illegal character in realm name; one of: '/', ':', '\0'");
		errMsgList.put(new Integer(REALM_NULL), "Null realm name");

		errMsgList.put(new Integer(CCACHE_NOT_FOUND), "Credentials cache not found");
		errMsgList.put(new Integer(CCACHE_INVALID_TYPE), "Invalid credentials cache type");

		errMsgList.put(new Integer(KT_FILE_NOT_FOUND), "Keytab file not found");
		errMsgList.put(new Integer(KT_FILE_CORRUPT), "Keytab file corrupt");
		errMsgList.put(new Integer(KT_FILE_VERSION_UNSUPPORTED), "Keytab file version unsupported");
		errMsgList.put(new Integer(KT_FILE_ENTRY_NOT_FOUND), "Keytab file entry not found");

		errMsgList.put(new Integer(ASN1_BAD_TIMEFORMAT), "Input not in GeneralizedTime format");
		errMsgList.put(new Integer(ASN1_MISSING_FIELD), "Structure is missing a required field");
		errMsgList.put(new Integer(ASN1_MISPLACED_FIELD), "Unexpected field number");
		errMsgList.put(new Integer(ASN1_TYPE_MISMATCH), "Type numbers are inconsistent");
		errMsgList.put(new Integer(ASN1_OVERFLOW), "Value too large");
		errMsgList.put(new Integer(ASN1_OVERRUN), "Encoding ended unexpectedly");
		errMsgList.put(new Integer(ASN1_BAD_ID), "Identifier doesn't match expected value");
		errMsgList.put(new Integer(ASN1_BAD_LENGTH), "Length doesn't match expected value");
		errMsgList.put(new Integer(ASN1_BAD_FORMAT), "Badly-formatted encoding");
		errMsgList.put(new Integer(ASN1_PARSE_ERROR), "Parse error");
		errMsgList.put(new Integer(ASN1_BAD_CLASS), "Bad class number");
		errMsgList.put(new Integer(ASN1_BAD_TYPE), "Bad type number");
		errMsgList.put(new Integer(ASN1_BAD_TAG), "Bad tag number");
		errMsgList.put(new Integer(ASN1_UNSUPPORTED_TYPE), "Unsupported ASN.1 type encountered");
		errMsgList.put(new Integer(ASN1_CANNOT_ENCODE), "Encoding failed due to invalid parameter(s)");

		errMsgList.put(new Integer(CONF_FILE_NOT_FOUND), "Config file not found");
		errMsgList.put(new Integer(CONF_FILE_READ_FAILED), "Config file read failed");
		errMsgList.put(new Integer(CONF_FILE_PARSE_FAILURE), "Config file parse failure");

	}

}