<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="../../resources/stylesheets/wasmsgxml.css"?>
<TMSSource name="TivoliMessages" tmsVersion="1.0" xml:lang="en">
<!-- CMVC MSG File Name = SERV1/ws/code/security.sas/src/com/ibm/ws/security/auth/kerberos/krbsecurity.nlsprops -->
<!-- DO NOT EDIT THIS FILE - This file was generated by the XML/Html & Property emitter -->
<!-- BEGIN MESSAGES -->
<Message ID="SECJ9333W" severity="W" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.cannot.resetkeytab" varFormat="Java">
    security.auth.kerberos.cannot.resetkeytab=SECJ9333W: Can not reset a system property KRB5_KTNAME (Kerberos keytab file) to {0} because it already set for {1}. The runtime still use the Kerberos keytab file {2}
  </MsgText>
  <Explanation>
    The system property for KRB5_KTNAME (Kerberos keytab file) does not allow to re-set.
  </Explanation>
  <UserResponse>
    none.
  </UserResponse>
</Message>
<Message ID="SECJ9329E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.init.crednotforwardable" varFormat="Java">
    security.auth.kerberos.init.crednotforwardable=SECJ9329E: Credential {0}, is not forwardable for target GSS service name {1} in the realm {2}
  </MsgText>
  <Explanation>
    Credential is not fowardable.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9317E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.CredInvalid" varFormat="Java">
    security.auth.kerberos.CredInvalid=SECJ9317E: The credential is invalid.
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9204E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.CredExpired" varFormat="Java">
    security.auth.kerberos.CredExpired=SECJ9204E: Credential in invalid state.
  </MsgText>
  <Explanation>
    Access to an expired credential has been attempted.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9316E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.GSSException" varFormat="Java">
    security.auth.kerberos.GSSException=SECJ9316E: An unexpected GSSexception occurred when trying to run {0} method : GSSException: {1}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause
  </UserResponse>
</Message>
<Message ID="SECJ9201W" severity="W" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.MultipleCredsFound" varFormat="Java">
    security.auth.kerberos.MultipleCredsFound=SECJ9201W: Multiple Kerberos credentials found in subject private credential set; using first credential in set.
  </MsgText>
  <Explanation>
    There are multiple Kerberos credentials in the credential set of the subject. Authentication will continue using the first credential in the set.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9320E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.ValidateException" varFormat="Java">
    security.auth.kerberos.ValidateException=SECJ9320E: Validation of the Kerberos token threw the following exception: {0}
  </MsgText>
  <Explanation>
    Validation of the Kerberos token threw an unexpected exception
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9200E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.NoCredFound" varFormat="Java">
    security.auth.kerberos.NoCredFound=SECJ9200E: No Kerberos credential found in subject credential set.
  </MsgText>
  <Explanation>
    No kerberos credential was found in the JAAS Subject private credential set.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9304E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapNoDefaultRule" varFormat="Java">
    security.auth.kerberos.PrincipalMapNoDefaultRule=SECJ9304E: No default rule found in map file &apos;&apos;{0}&apos;&apos;.
  </MsgText>
  <Explanation>
    The required default catch-all rule was not found in the principal map file.
  </Explanation>
  <UserResponse>
    Ensure that there is a default catch-all rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9322E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.RemPrincException" varFormat="Java">
    security.auth.kerberos.RemPrincException=SECJ9322E: Remove principal from subject threw the following exception: {0}
  </MsgText>
  <Explanation>
    Remove principal from subject threw an unexpected exception.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9206W" severity="W" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.noDelegatedCredentialsFound" varFormat="Java">
    security.auth.kerberos.noDelegatedCredentialsFound=SECJ9206W: No GSS delegated credentials were found for user: {0}
  </MsgText>
  <Explanation>
    No GSS delegated credentials found after validate the Kerberos request.
  </Explanation>
  <UserResponse>
    Make sure client have a forwardable Kerberos ticket (TGT) and server is trusted for delegation.
  </UserResponse>
</Message>
<Message ID="SECJ9324E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.DestroyCredException" varFormat="Java">
    security.auth.kerberos.DestroyCredException=SECJ9324E: Destroy credential from subject threw the following exception: {0}
  </MsgText>
  <Explanation>
    Destroy credential from subject threw an unexpected exception.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9332E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.complete.initnotcalled" varFormat="Java">
    security.auth.kerberos.complete.initnotcalled=SECJ9332E: The complete initSecContext() method is not called {0}
  </MsgText>
  <Explanation>
    The complete initSecContext method is not called.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9203E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.CredDestroyed" varFormat="Java">
    security.auth.kerberos.CredDestroyed=SECJ9203E: Credential in invalid state.
  </MsgText>
  <Explanation>
    Access to a destroyed credential has been attempted.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9314E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.unexpectedexception" varFormat="Java">
    security.auth.kerberos.unexpectedexception=SECJ9314E: An unexpected exception occurred when trying to run {0} method : GSSException: {1}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9302E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapDuplicateDefaultRule" varFormat="Java">
    security.auth.kerberos.PrincipalMapDuplicateDefaultRule=SECJ9302E: Duplicate default catch-all rule found in map file &apos;&apos;{0}&apos;&apos; at line {1}.
  </MsgText>
  <Explanation>
    A duplicate default catch-all rule was found in the principal map file.
  </Explanation>
  <UserResponse>
    Correct the error in principal map file.
  </UserResponse>
</Message>
<Message ID="SECJ9331E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.nullconstructor" varFormat="Java">
    security.auth.kerberos.nullconstructor=SECJ9331E: The constructor for the class {0} does not allow null {1}
  </MsgText>
  <Explanation>
    The token is null.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9202E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.GSSCredCopyFailed" varFormat="Java">
    security.auth.kerberos.GSSCredCopyFailed=SECJ9202E: Copy operation on GSS credential failed. GSS Exception: {0}
  </MsgText>
  <Explanation>
    A GSS exception occurred while making a copy of a GSSCredential.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9330E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.init.nullcred" varFormat="Java">
    security.auth.kerberos.init.nullcred=SECJ9330E: Credential is null for target GSS service name {0} in the realm {1}
  </MsgText>
  <Explanation>
    Credential is null
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9312E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapServerRootNotSet" varFormat="Java">
    security.auth.kerberos.PrincipalMapServerRootNotSet=SECJ9312E: System property &quot;server.root&quot; not set.
  </MsgText>
  <Explanation>
    The system property &quot;server.root&quot; is not set.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9308E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapRuleMissingRHS" varFormat="Java">
    security.auth.kerberos.PrincipalMapRuleMissingRHS=SECJ9308E: Principal map rule missing right-hand-side principal.
  </MsgText>
  <Explanation>
    Map rule must specify a principal on the right-hand-side of the colon character.
  </Explanation>
  <UserResponse>
    Correct the rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9205E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.UserRegError" varFormat="Java">
    security.auth.kerberos.UserRegError=SECJ9205E: User registry error: {0}
  </MsgText>
  <Explanation>
    An error was encountered accessing the user registry.
  </Explanation>
  <UserResponse>
    Check user registry configuration.
  </UserResponse>
</Message>
<Message ID="SECJ9326E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.init.ctxnotestablished" varFormat="Java">
    security.auth.kerberos.init.ctxnotestablished=SECJ9326E: Security context is not established for GSSContext {0}
  </MsgText>
  <Explanation>
    Security context is not established.
  </Explanation>
  <UserResponse>
    Examine SystemErr.log to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9301E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapError" varFormat="Java">
    security.auth.kerberos.PrincipalMapError=SECJ9301E: Error in principal map file &apos;&apos;{0}&apos;&apos; at line {1}: {2}
  </MsgText>
  <Explanation>
    An error was encountered while reading the principal map file.
  </Explanation>
  <UserResponse>
    Correct the error in principal map file.
  </UserResponse>
</Message>
<Message ID="SECJ9207E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.gssUserNameIsNull" varFormat="Java">
    security.auth.kerberos.gssUserNameIsNull=SECJ9207E: GSS user name is null, {0}
  </MsgText>
  <Explanation>
    GSS user name is null.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9300E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapNotFound" varFormat="Java">
    security.auth.kerberos.PrincipalMapNotFound=SECJ9300E: Principal map file &apos;&apos;{0}&apos;&apos; not found or inaccessible.
  </MsgText>
  <Explanation>
    The specified principal map file was not found or is inaccessible.
  </Explanation>
  <UserResponse>
    Ensure that the file exists and is accessible.
  </UserResponse>
</Message>
<Message ID="SECJ9309E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapRuleMalformedLHS" varFormat="Java">
    security.auth.kerberos.PrincipalMapRuleMalformedLHS=SECJ9309E: Error in left-hand-side of principal map rule.
  </MsgText>
  <Explanation>
    Left-hand-side of principal map rule must be one of: &apos;principal@realm&apos;, &apos;*@realm&apos;, or &apos;*&apos;.
  </Explanation>
  <UserResponse>
    Correct the rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9310E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapRuleMissingLHSPrincipal" varFormat="Java">
    security.auth.kerberos.PrincipalMapRuleMissingLHSPrincipal=SECJ9310E: Principal map rule missing left-hand-side principal.
  </MsgText>
  <Explanation>
    Map rule must specify a principal on the left-hand-side of the colon character.
  </Explanation>
  <UserResponse>
    Correct the rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9311E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapRuleMissingLHSRealm" varFormat="Java">
    security.auth.kerberos.PrincipalMapRuleMissingLHSRealm=SECJ9311E: Principal map rule missing left-hand-side realm.
  </MsgText>
  <Explanation>
    Map rule must specify a realm on the left-hand-side of the colon character.
  </Explanation>
  <UserResponse>
    Correct the rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9307E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapRuleMissingLHS" varFormat="Java">
    security.auth.kerberos.PrincipalMapRuleMissingLHS=SECJ9307E: Principal map rule missing left-hand-side principal and realm.
  </MsgText>
  <Explanation>
    Map rule must specify a principal and realm on the left-hand-side of the colon character.
  </Explanation>
  <UserResponse>
    Correct the rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9400W" severity="W" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.cannot.getSPNonClient" varFormat="Java">
    security.auth.kerberos.cannot.getSPNonClient=SECJ9400W: The kerberos Service Principal Name cannot be determined when running on the client. A null value will be returned.
  </MsgText>
  <Explanation>
    When this method is invoked on the client side, it is not possible to determine the Kerberos Service Principal Name, and therefore a null value is returned.
  </Explanation>
  <UserResponse>
    Do not invoke this method on the client side.
  </UserResponse>
</Message>
<Message ID="SECJ9325E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.CredUtilsException" varFormat="Java">
    security.auth.kerberos.CredUtilsException=SECJ9325E: Create credential threw the following exception: {0}
  </MsgText>
  <Explanation>
    Create credential threw an unexpected exception.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9313W" severity="W" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.RealmMismatch" varFormat="Java">
    security.auth.kerberos.RealmMismatch=SECJ9313W: The Kerberos realm name specified in the callback handler, {0}, does not match the Kerberos realm name specified in the Kerberos configuration: {1} or the default realm: {2}.  The login will proceed since both WebSphere and the Tivoli login modules do not check the realm names.
  </MsgText>
  <Explanation>
    The Kerberos realm name specified in the callback handler does not match the Kerberos realm name or the default realm name, but the login will proceed anyway.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9323E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.RemCredException" varFormat="Java">
    security.auth.kerberos.RemCredException=SECJ9323E: Remove public credential from subject threw the following exception: {0}
  </MsgText>
  <Explanation>
    Remove public credential from subject threw an unexpected exception.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9321E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.DoPrivException" varFormat="Java">
    security.auth.kerberos.DoPrivException=SECJ9321E: doPrivileged method threw the following exception: {0}
  </MsgText>
  <Explanation>
    doPrivileged method threw an unexpected exception.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9319E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.LoginException" varFormat="Java">
    security.auth.kerberos.LoginException=SECJ9319E: Login failed for user {0}; the exception is {1}
  </MsgText>
  <Explanation>
    A login failed for the user.
  </Explanation>
  <UserResponse>
    None.
  </UserResponse>
</Message>
<Message ID="SECJ9315E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.exception" varFormat="Java">
    security.auth.kerberos.exception=SECJ9315E: Unexpected exception occurred when trying to run {0} method : Exception: {1}
  </MsgText>
  <Explanation>
    This exception is unexpected. The cause is not immediately known.
  </Explanation>
  <UserResponse>
    Examine the associated exception to determine the cause.
  </UserResponse>
</Message>
<Message ID="SECJ9306E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapRuleMissingColon" varFormat="Java">
    security.auth.kerberos.PrincipalMapRuleMissingColon=SECJ9306E: Principal map rule missing required colon character (&apos;:&apos;).
  </MsgText>
  <Explanation>
    Each map rule must contain a colon character.
  </Explanation>
  <UserResponse>
    Correct the rule in the map file.
  </UserResponse>
</Message>
<Message ID="SECJ9305E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapErrorsFound" varFormat="Java">
    security.auth.kerberos.PrincipalMapErrorsFound=SECJ9305E: Errors were encountered processing map file &apos;&apos;{0}&apos;&apos;.
  </MsgText>
  <Explanation>
    Errors were encountered processing map file.
  </Explanation>
  <UserResponse>
    Correct the error in principal map file.
  </UserResponse>
</Message>
<Message ID="SECJ9303E" severity="E" prefix="yes">
  <MsgText pgmKey="security.auth.kerberos.PrincipalMapIOException" varFormat="Java">
    security.auth.kerberos.PrincipalMapIOException=SECJ9303E: IOException caught reading principal map file &apos;&apos;{0}&apos;&apos;.
  </MsgText>
  <Explanation>
    An input/output exception was encountered while reading the principal map file.
  </Explanation>
  <UserResponse>
    Make sure the file exists and is readable.
  </UserResponse>
</Message>
<!-- END MESSAGES -->
</TMSSource>
