Kerberos: Clock skew too great (KRB_AP_ERR_SKEW)
The client’s clock differs from the domain controller’s by more than 5 minutes, so Kerberos tickets are rejected.
Seen on:
REST API
Meaning
Kerberos timestamps protect against replay. VMs resumed from suspend, containers with drifted clocks, or machines not syncing with the domain’s time source fail authentication (SSO, SMB, SQL Server, Hadoop).
Common causes
- System clock drift (VMs, dual boot, containers)
- Time zone misconfiguration
- NTP not syncing with the domain hierarchy
⚡ Quick fix
- Sync time with the domain (w32tm /resync or NTP)
- Fix time zone settings
- Ensure VMs use host/NTP time sync
Detailed fix by platform
Windows
- powershell
w32tm /query /status w32tm /resync /force
Linux
- bash
timedatectl sudo chronyc tracking
How to diagnose
- Clocks — Client vs DC time
- Source — NTP configured?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
- invalid two-factor code Two-factor (TOTP) code invalid / Invalid verification code (authenticator app time drift)
- jwt not active NotBeforeError: jwt not active (nbf claim in the future)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026