Clock skew too great 🔐 Authentication

Kerberos: Clock skew too great (KRB_AP_ERR_SKEW)

The client’s clock differs from the domain controller’s by more than 5 minutes, so Kerberos tickets are rejected.

Seen on: REST API

Meaning

Kerberos timestamps protect against replay. VMs resumed from suspend, containers with drifted clocks, or machines not syncing with the domain’s time source fail authentication (SSO, SMB, SQL Server, Hadoop).

Common causes

  • System clock drift (VMs, dual boot, containers)
  • Time zone misconfiguration
  • NTP not syncing with the domain hierarchy

⚡ Quick fix

  1. Sync time with the domain (w32tm /resync or NTP)
  2. Fix time zone settings
  3. Ensure VMs use host/NTP time sync

Detailed fix by platform

Windows

  1. powershell
    w32tm /query /status
    w32tm /resync /force

Linux

  1. bash
    timedatectl
    sudo chronyc tracking

How to diagnose

  1. Clocks — Client vs DC time
  2. Source — NTP configured?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.