please check the two cap file attached.
there is a e-data at the end of the last frame in both files. there is a NTstatus code is the e-date file. but Wireshark parsered the one in KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN.cap but not "KRB5KDC_ERR_CLIENT_REVOKED for
AS.cap". the NTstatus code is very helpful for trouble shooting kerberos issues. So it will be great if this problem can be fixed.
Version 0.99.6-SVN-20621 (SVN Rev 20621) on xp sp2
Attachment:
KRB5KDC_ERR_CLIENT_REVOKED for AS.cap
Description: Binary data
Attachment:
KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN.cap
Description: Binary data