<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-Security-Kerberos" version="10.0.10586.306" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="Resources">
    <dependentAssembly>
      <assemblyIdentity name="Microsoft-Windows-Security-Kerberos.Resources" version="10.0.10586.306" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
  </dependency>
  <file name="kerberos.dll" destinationPath="$(runtime.system32)\" sourceName="kerberos.dll" sourcePath=".\" importPath="$(build.nttree)\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2">
      <dsig:Transforms xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">qNqATbv14Y39zfcKDPW3Vibj1uXoolMlFmWpHfW8P/4=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories" version="1.0.0.0" publicKeyToken="365143bb27e7ac8b" typeName="LsaPackages" />
      <categoryInstance subcategory="Security Packages">
        <package xmlns="urn:schemas-microsoft-com:asm.v3" name="kerberos" position="last" />
      </categoryInstance>
    </categoryMembership>
  </memberships>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Kerberos">
      <registryValue name="EventMessageFile" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\kerberos.dll" />
      <registryValue name="TypesSupported" valueType="REG_DWORD" value="0x00000007" />
      <registryValue name="ProviderGuid" valueType="REG_EXPAND_SZ" value="{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)" operationHint="replace" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="ClientCertificateValidationFailure" value="Trust validation of the client certificate for %1 failed: %2 on KDC. Use the CAPI2 diagnostic traces to identify the reason for the validation failure." />
        <string id="CredmanCredentialFound" value="The Kerberos client used credentials from the Credential Manager for the target: '%1'." />
        <string id="DcFound" value="The Kerberos client discovered domain controller %1 for the domain %2." />
        <string id="DcNotAccessible" value="The Kerberos client was bound to domain controller %1 for the domain %2 but could not access this domain controller at the time.%n%n    DesiredFlags: %3%n    CacheFlags: %4%n    ErrorCode: %5" />
        <string id="description1" value="Implements the client side Kerberos component." />
        <string id="displayName0" value="Kerberos" />
        <string id="DuplicateSpnFound" value="The service principal name (SPN) %1 is registered on multiple accounts which caused Kerberos authentication to fail: %2. Use the setspn command-line tool to identify the accounts and remove the duplicate registrations." />
        <string id="event_EVENT_ID_BUILDCC" value="An error occurred while building a certificate context: %1" />
        <string id="event_EVENT_ID_DECMSG" value="An error occurred while decrypting a message using the inserted smart card: %1" />
        <string id="event_EVENT_ID_DECMSG_NOSC" value="An error occurred while decrypting a message: %1" />
        <string id="event_EVENT_ID_ENCMSG" value="An error occurred while encrypting a message using the inserted smart card: %1" />
        <string id="event_EVENT_ID_ENCMSG_NOSC" value="An error occurred while encrypting a message: %1" />
        <string id="event_EVENT_ID_GENRANDBITS" value="An error occurred while generating a random number: %1" />
        <string id="event_EVENT_ID_GETCERT" value="An error occurred while retrieving a digital certificate from the inserted smart card. %1" />
        <string id="event_EVENT_ID_GETPROVPARAM" value="An error occurred while retrieving some provider parameter: %1" />
        <string id="event_EVENT_ID_INITIALIZE" value="An error occurred while initializing the smart card logon library: %1" />
        <string id="event_EVENT_ID_SIGNMSG" value="An error occurred while signing a message using the inserted smart card: %1" />
        <string id="event_EVENT_ID_SIGNMSG_NOSC" value="An error occurred while signing a message: %1" />
        <string id="event_EVENT_ID_VERIFYCARD" value="An error occurred in while attempting to verify the inserted smart card: %1" />
        <string id="event_EVENT_ID_VERIFYCERT" value="An error occurred while verifying the digital certificate retrieved from the inserted smart card: %1" />
        <string id="event_EVENT_ID_VERIFYMSG" value="An error occurred while verifying a signed message using the inserted smart card: %1" />
        <string id="event_EVENT_ID_VERIFYMSG_NOSC" value="An error occurred while verifying a signed message: %1" />
        <string id="event_KERBEVT_BAD_CLIENT_CERTIFICATE" value="The domain controller rejected the client certificate of user %2, used for smart card logon. The following error was returned from the certificate validation process: %1." />
        <string id="event_KERBEVT_BAD_KDC_CERTIFICATE" value="The client has failed to validate the domain controller certificate for %2. The following error was returned from the certificate validation process: %1." />
        <string id="event_KERBEVT_CERTIFICATE_STORE_ERROR" value="The Kerberos SSPI package failed to find the smart card certificate in the certificate store. To remedy this failure, logon as user %1 and insert the smart card into the smart card reader, then use the Certificates snap-in to verify that the smart card certificate is in the user's personal certificate store." />
        <string id="event_KERBEVT_CREDMAN_CARD_ERROR" value="The smart card PIN stored in Credential Manager is missing or invalid. The smart card PIN is stored in memory only for the current interactive logon session, and is deleted if the card is removed from the card reader or when the user logs off. To resolve this error, keep the card in the reader, open Credential Manager in Control Panel, and reenter the PIN for the credential %1." />
        <string id="event_KERBEVT_CREDMAN_PWD_ERROR" value="The password stored in Credential Manager is invalid. This might be caused by the logged on user changing the password from this computer or a different computer. To resolve this error, open Credential Manager in Control Panel, and reenter the password for the credential %1." />
        <string id="event_KERBEVT_DELEGATED_TGT_EXPIRED" value="The delegated TGT for the user (%2) has expired. A renewal was attempted and failed with error %8. The server logon session (%1) has stopped delegating the user's credential. For future unconstrained delegation to succeed, the user needs to authenticate again to the server. %n%nTGT Details:%n    Client: %2%n    Server: %3%n    Flags: %4%n    Start Time: %5%n    End Time: %6%n    Renew Until: %7" />
        <string id="event_KERBEVT_FSO_INVALID_FOREST" value="The Kerberos SSPI package failed to locate the forest or domain %1 to search.  Ensure that the Use forest search order Group Policy is correctly configured, and that this forest or domain is available." />
        <string id="event_KERBEVT_INSUFFICIENT_TOKEN_SIZE" value="The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by process id %3.%n %n The output SSPI token size is probably the result of the user %4 being a member of a large number of groups.%n %n It is recommended to minimize the number of groups a user belongs to. If the problem can not be corrected by reducing the group memberships of this user, contact your system administrator to increase the maximum token size, which is configured on each computer individually using the registry value: HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\MaxTokenSize." />
        <string id="event_KERBEVT_KDC_CERT_DOMAIN_NAME_MISMATCH" value="The KDC certificate for the domain controller does not have the DNS name of domain %1 in the Subject Alternative Name (SAN) attribute: Error Code %2. The domain administrator will need to obtain a KDC certificate with the DNS domain name in the SAN attribute for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template." />
        <string id="event_KERBEVT_KDC_CERT_MISSING_KDC_EKU" value="The KDC certificate for the domain controller does not contain the KDC Extended Key Usage (EKU): 1.3.6.1.5.2.3.5: Error Code %1. The domain administrator will need to obtain a certificate with the KDC EKU for the domain controller to resolve this error. When using Windows Server Certificate Services create a certificated based on the Kerberos Authentication Template." />
        <string id="event_KERBEVT_KERB_ERROR_MSG" value="A Kerberos error message was received:%n on logon session %1%n Client Time: %2%n Server Time: %3%n Error Code: %4 %5%n Extended Error: %6%n Client Realm: %7%n Client Name: %8%n Server Realm: %9%n Server Name: %10%n Target Name: %11%n Error Text: %12%n File: %13%n Line: %14%n Error Data is in record data." />
        <string id="event_KERBEVT_KRB_AP_ERR_MODIFIED" value="The Kerberos client received a KRB_AP_ERR_MODIFIED error from the server %1. The target name used was %3. This indicates that the target server failed to decrypt the ticket provided by the client. This can occur when the target server principal name (SPN) is registered on an account other than the account the target service is using. Ensure that the target SPN is only registered on the account used by the server. This error can also happen if the target service account password is different than what is configured on the Kerberos Key Distribution Center for that target service. Ensure that the service on the server and the KDC are both configured to use the same password. If the server name is not fully qualified, and the target domain (%2) is different from the client domain (%4), check if there are identically named server accounts in these two domains, or use the fully-qualified name to identify the server." />
        <string id="event_KERBEVT_KRB_AP_ERR_TKT_NYV" value="The Kerberos client received a KRB_AP_ERR_TKT_NYV error from the server %1. This indicates that the ticket presented to that server is not yet valid (due to a discrepancy between ticket and server time. Contact your system administrator to make sure the client and server times are synchronized, and that the time for the Key Distribution Center Service (KDC) in realm %2 is synchronized with the KDC in the client realm." />
        <string id="event_KERBEVT_KRB_PAC_VERIFICATION_FAILURE" value="The digitally signed Privilege Attribute Certificate (PAC) that contains the authorization information for client %1 in realm %2 could not be validated.%n %n This error is usually caused by domain trust failures; Contact your system administrator." />
        <string id="event_KERBEVT_NO_RDN" value="The Distinguished Name in the subject field of your smart card logon certificate does not contain enough information to identify the appropriate domain on an non-domain joined computer. Contact your system administrator." />
        <string id="event_KERBEVT_RAS_CARD_ERROR" value="While using your smart card over a VPN connection, the Kerberos subsystem encountered an error. Typically, this indicates the card has been pulled from the card reader during the VPN session. One possible solution is to close the VPN connection, reinsert the card, and establish the connection again." />
        <string id="event_KERBEVT_TOKEN_SIZE_TOO_SMALL" value="The Kerberos SSPI package generated an output token of size %1 bytes, which was too large to fit in the token buffer of size %2 bytes, provided by process id %3.%n %n The application needs to be modified to supply a token buffer of size at least %4 bytes." />
        <string id="event_KERBEVT_UDP_TIMEOUT" value="The Kerberos subsystem currently cannot retrieve tickets from your domain controller using the UDP network protocol. This is typically due to network problems. Contact your system administrator." />
        <string id="eventProviderName" value="Microsoft-Windows-Security-Kerberos" />
        <string id="FailureLocatingDc" value="The Kerberos client could not locate a domain controller for domain %1: %2. Kerberos authentication requires communicating with a domain controller." />
        <string id="GmsaBuildPasswords" value="The Kerberos client updated passwords for the group managed service account.%n%nLogonId: %1:%2%nDomainName: %3%nUserName: %4%nUpdate Current Passwords: %5%nUpdate Old Passwords: %6%nRefresh: %7%nPrevious File Time: %8%nCurrent File Time: %9%n" />
        <string id="GmsaGetPasswordsFailure" value="The Kerberos client could not retrieve passwords for the group managed service account.%n%nLogonId: %1:%2%nDomainName: %3%nUserName: %4%nRefresh: %5%nCurrent File Time: %6%nError Code: %7%n" />
        <string id="KdcCertificateMissing" value="The Kerberos Key Distribution Center (KDC) for the domain %1 does not have a certificate installed or does not support logon using certificates: %2" />
        <string id="KdcCertificateValidationFailure" value="Trust validation of the certificate for the Kerberos Key Distribution Center (KDC) %1 failed: %2. Use the CAPI2 diagnostic traces to identify the reason for the validation failure." />
        <string id="KdcCertValidationDomainNameMismatch" value="The Kerberos client received a KDC certificate that does not have a matched domain name.%n%nExpected Domain Name: %1%nError Code: %2%n" />
        <string id="KdcCertValidationMissingKdcEku" value="The Kerberos client received a KDC certificate that does not have KDC EKU (not based on Kerberos Authentication Template).%n%nError Code: %1%n" />
        <string id="MissingSpn" value="The service principal name (SPN) %1 is not registered, which caused Kerberos authentication to fail: %2. Use the setspn command-line tool to register the SPN." />
        <string id="NoAuthProxyCred" value="The Kerberos client could not find a suitable credential to use with the authentication proxy:%n%nAuthProxy:%n  Proxy: %1%n  ProxyBypass: %2%n  Epoch: %3%n  Supported Schemes: %4%n  First Scheme: %5%nDigest Credential:%n  Initialized: %6%n  DomainAndUserName: %7%n  Epoch: %8%nBasic Credential:%n  Initialized: %9%n  DomainAndUserName: %10%n  Epoch: %11%n" />
        <string id="OperationalChannelName" value="Operational" />
        <string id="SendProxyRequestFailure" value="The Kerberos client could not send a Kerberos proxy request.%n%nProxyServer:%n  ServerName: %1%n  ServerPort: %2%n  ServerVdir:  %3%nError Code: %4%nStatus Code: %5%n" />
        <string id="task_CATEGORY_KERBEROS" value="Kerberos" />
        <string id="task_CATEGORY_MAX_CATEGORY" value="Max" />
      </stringTable>
    </resources>
  </localization>
  <instrumentation>
    <events xmlns="http://schemas.microsoft.com/win/2004/08/events">
      <provider guid="{98E6CFCB-EE0A-41E0-A57B-622D4E1B30B1}" message="$(string.eventProviderName)" messageFileName="%SystemRoot%\System32\kerberos.dll" name="Microsoft-Windows-Security-Kerberos" resourceFileName="%SystemRoot%\System32\kerberos.dll" symbol="S_Microsoft_Windows_Security_Kerberos">
        <channels>
          <channel chid="Operational" enabled="false" isolation="System" message="$(string.OperationalChannelName)" name="Microsoft-Windows-Kerberos/Operational" type="Operational" />
        </channels>
        <tasks>
          <task message="$(string.task_CATEGORY_KERBEROS)" name="CATEGORY_KERBEROS" symbol="CATEGORY_KERBEROS" value="0x0001" />
          <task message="$(string.task_CATEGORY_MAX_CATEGORY)" name="CATEGORY_MAX_CATEGORY" symbol="CATEGORY_MAX_CATEGORY" value="0x0002" />
        </tasks>
        <templates>
          <template tid="T_KERBEVT_KERB_ERROR_MSG">
            <data inType="win:UnicodeString" name="LogonSession" />
            <data inType="win:UnicodeString" name="ClientTime" />
            <data inType="win:UnicodeString" name="ServerTime" />
            <data inType="win:UnicodeString" name="ErrorCode" />
            <data inType="win:UnicodeString" name="ErrorMessage" />
            <data inType="win:UnicodeString" name="ExtendedError" />
            <data inType="win:UnicodeString" name="ClientRealm" />
            <data inType="win:UnicodeString" name="ClientName" />
            <data inType="win:UnicodeString" name="ServerRealm" />
            <data inType="win:UnicodeString" name="ServerName" />
            <data inType="win:UnicodeString" name="TargetName" />
            <data inType="win:UnicodeString" name="ErrorText" />
            <data inType="win:UnicodeString" name="File" />
            <data inType="win:UnicodeString" name="Line" />
            <binary />
          </template>
          <template tid="T_KERBEVT_KRB_AP_ERR_MODIFIED">
            <data inType="win:UnicodeString" name="Server" />
            <data inType="win:UnicodeString" name="TargetRealm" />
            <data inType="win:UnicodeString" name="Targetname" />
            <data inType="win:UnicodeString" name="ClientRealm" />
            <binary />
          </template>
          <template tid="T_KERBEVT_KRB_AP_ERR_TKT_NYV">
            <data inType="win:UnicodeString" name="Server" />
            <data inType="win:UnicodeString" name="KDCRealm" />
            <binary />
          </template>
          <template tid="T_KERBEVT_INSUFFICIENT_TOKEN_SIZE">
            <data inType="win:UnicodeString" name="NeededSize" />
            <data inType="win:UnicodeString" name="ActualSize" />
            <data inType="win:UnicodeString" name="ClientProcessID" />
            <data inType="win:UnicodeString" name="ClientName" />
            <binary />
          </template>
          <template tid="T_KERBEVT_KRB_PAC_VERIFICATION_FAILURE">
            <data inType="win:UnicodeString" name="ClientName" />
            <data inType="win:UnicodeString" name="Realm" />
            <binary />
          </template>
          <template tid="T_KERBEVT_BAD_CLIENT_CERTIFICATE">
            <data inType="win:UnicodeString" name="Name" />
            <data inType="win:UnicodeString" name="Message" />
            <binary />
          </template>
          <template tid="T_KERBEVT_BAD_KDC_CERTIFICATE">
            <data inType="win:UnicodeString" name="Name" />
            <data inType="win:UnicodeString" name="Message" />
            <binary />
          </template>
          <template tid="T_KERBEVT_CREDMAN_CARD_ERROR">
            <data inType="win:UnicodeString" name="Username" />
            <binary />
          </template>
          <template tid="T_KERBEVT_CREDMAN_PWD_ERROR">
            <data inType="win:UnicodeString" name="Username" />
            <binary />
          </template>
          <template tid="T_KERBEVT_TOKEN_SIZE_TOO_SMALL">
            <data inType="win:UnicodeString" name="NeededSize" />
            <data inType="win:UnicodeString" name="ActualSize" />
            <data inType="win:UnicodeString" name="ClientProcessID" />
            <data inType="win:UnicodeString" name="RequiredSize" />
            <binary />
          </template>
          <template tid="T_SCLMSG">
            <data inType="win:UnicodeString" name="Error" />
            <binary />
          </template>
          <template tid="T_KERBEVT_CERTIFICATE_STORE_ERROR">
            <data inType="win:UnicodeString" name="Username" />
            <binary />
          </template>
          <template tid="T_KERBEVT_FSO_INVALID_FOREST">
            <data inType="win:UnicodeString" name="Forest" />
            <binary />
          </template>
          <template tid="T_KERBEVT_DELEGATED_TGT_EXPIRED">
            <data inType="win:UnicodeString" name="Luid" />
            <data inType="win:UnicodeString" name="ClientPrincipalName" />
            <data inType="win:UnicodeString" name="ServicePrincipalName" />
            <data inType="win:UnicodeString" name="TicketFlags" />
            <data inType="win:UnicodeString" name="StartTime" />
            <data inType="win:UnicodeString" name="EndTime" />
            <data inType="win:UnicodeString" name="RenewUntil" />
            <data inType="win:UnicodeString" name="ErrorCode" />
          </template>
          <template tid="T_KERBEVT_KDC_CERT_MISSING_KDC_EKU">
            <data inType="win:UnicodeString" name="ErrorCode" />
          </template>
          <template tid="T_KERBEVT_KDC_CERT_DOMAIN_NAME_MISMATCH">
            <data inType="win:UnicodeString" name="DomainName" />
            <data inType="win:UnicodeString" name="ErrorCode" />
          </template>
          <template tid="T_FAILURE_LOCATING_DC">
            <data inType="win:UnicodeString" name="TargetDomain" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_DC_FOUND">
            <data inType="win:UnicodeString" name="DomainController" />
            <data inType="win:UnicodeString" name="TargetDomain" />
          </template>
          <template tid="T_DC_NOT_ACCESSIBLE">
            <data inType="win:UnicodeString" name="DomainController" />
            <data inType="win:UnicodeString" name="TargetDomain" />
            <data inType="win:UInt32" name="DesiredFlags" />
            <data inType="win:UInt32" name="CacheFlags" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_GMSA_BUILD_PASSWORDS">
            <data inType="win:UInt32" name="LuidHighPart" outType="win:HexInt32" />
            <data inType="win:UInt32" name="LuidLowPart" outType="win:HexInt32" />
            <data inType="win:UnicodeString" name="DomainName" />
            <data inType="win:UnicodeString" name="UserName" />
            <data inType="win:Boolean" name="UpdateCurrent" />
            <data inType="win:Boolean" name="UpdateOld" />
            <data inType="win:Boolean" name="Refresh" />
            <data inType="win:UnicodeString" name="LastFileTime" />
            <data inType="win:UnicodeString" name="CurrentFileTime" />
          </template>
          <template tid="T_DUPLICATE_SPN_FOUND">
            <data inType="win:UnicodeString" name="SPN" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_MISSING_SPN">
            <data inType="win:UnicodeString" name="SPN" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_KDC_CERTIFICATE_VALIDATION_FAILURE">
            <data inType="win:UnicodeString" name="DomainController" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_CLIENT_CERTIFICATE_VALIDATION_FAILURE">
            <data inType="win:UnicodeString" name="ClientUpn" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_KDC_CERTIFICATE_MISSING">
            <data inType="win:UnicodeString" name="TargetDomain" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_GMSA_GET_PASSWORDS_FAILURE">
            <data inType="win:UInt32" name="LuidHighPart" outType="win:HexInt32" />
            <data inType="win:UInt32" name="LuidLowPart" outType="win:HexInt32" />
            <data inType="win:UnicodeString" name="DomainName" />
            <data inType="win:UnicodeString" name="UserName" />
            <data inType="win:Boolean" name="Refresh" />
            <data inType="win:UnicodeString" name="CurrentFileTime" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_KDC_CERT_VALIDATION_MISSING_KDC_EKU">
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_KDC_CERT_VALIDATION_DOMAIN_NAME_MISMATCH">
            <data inType="win:UnicodeString" name="ExpectedDomainName" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
          </template>
          <template tid="T_SEND_PROXY_REQUEST_FAILURE">
            <data inType="win:UnicodeString" name="ServerName" />
            <data inType="win:UInt32" name="ServerPort" />
            <data inType="win:UnicodeString" name="ServerVdir" />
            <data inType="win:UInt32" name="ErrorCode" outType="win:ErrorCode" />
            <data inType="win:UInt32" name="Status" outType="win:ErrorCode" />
          </template>
          <template tid="T_NO_AUTH_PROXY_CRED">
            <data inType="win:UnicodeString" name="Proxy" />
            <data inType="win:UnicodeString" name="ProxyBypass" />
            <data inType="win:UInt32" name="ProxyEpoch" />
            <data inType="win:UInt32" name="SupportedSchemes" />
            <data inType="win:UInt32" name="FirstScheme" />
            <data inType="win:Boolean" name="DigestCredInitialized" />
            <data inType="win:UnicodeString" name="DigestCredDomainAndUserName" />
            <data inType="win:UInt32" name="DigestCredEpoch" />
            <data inType="win:Boolean" name="BasicCredInitialized" />
            <data inType="win:UnicodeString" name="BasicCredDomainAndUserName" />
            <data inType="win:UInt32" name="BasicCredEpoch" />
          </template>
          <template tid="T_CREDMAN_CREDENTIAL_FOUND">
            <data inType="win:UnicodeString" name="Target" />
          </template>
        </templates>
        <events>
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_KERB_ERROR_MSG)" symbol="KERBEVT_KERB_ERROR_MSG" template="T_KERBEVT_KERB_ERROR_MSG" value="0x80000003" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_KRB_AP_ERR_MODIFIED)" symbol="KERBEVT_KRB_AP_ERR_MODIFIED" template="T_KERBEVT_KRB_AP_ERR_MODIFIED" value="0x40000004" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_KRB_AP_ERR_TKT_NYV)" symbol="KERBEVT_KRB_AP_ERR_TKT_NYV" template="T_KERBEVT_KRB_AP_ERR_TKT_NYV" value="0x40000005" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_INSUFFICIENT_TOKEN_SIZE)" symbol="KERBEVT_INSUFFICIENT_TOKEN_SIZE" template="T_KERBEVT_INSUFFICIENT_TOKEN_SIZE" value="0x80000006" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_KRB_PAC_VERIFICATION_FAILURE)" symbol="KERBEVT_KRB_PAC_VERIFICATION_FAILURE" template="T_KERBEVT_KRB_PAC_VERIFICATION_FAILURE" value="0xC0000007" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_BAD_CLIENT_CERTIFICATE)" symbol="KERBEVT_BAD_CLIENT_CERTIFICATE" template="T_KERBEVT_BAD_CLIENT_CERTIFICATE" value="0xC0000008" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_BAD_KDC_CERTIFICATE)" symbol="KERBEVT_BAD_KDC_CERTIFICATE" template="T_KERBEVT_BAD_KDC_CERTIFICATE" value="0xC0000009" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_UDP_TIMEOUT)" symbol="KERBEVT_UDP_TIMEOUT" value="0x8000000A" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_NO_RDN)" symbol="KERBEVT_NO_RDN" value="0xC000000B" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_RAS_CARD_ERROR)" symbol="KERBEVT_RAS_CARD_ERROR" value="0x8000000C" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_CREDMAN_CARD_ERROR)" symbol="KERBEVT_CREDMAN_CARD_ERROR" template="T_KERBEVT_CREDMAN_CARD_ERROR" value="0x8000000D" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_CREDMAN_PWD_ERROR)" symbol="KERBEVT_CREDMAN_PWD_ERROR" template="T_KERBEVT_CREDMAN_PWD_ERROR" value="0x8000000E" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_TOKEN_SIZE_TOO_SMALL)" symbol="KERBEVT_TOKEN_SIZE_TOO_SMALL" template="T_KERBEVT_TOKEN_SIZE_TOO_SMALL" value="0x8000000F" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_CERTIFICATE_STORE_ERROR)" symbol="KERBEVT_CERTIFICATE_STORE_ERROR" template="T_KERBEVT_CERTIFICATE_STORE_ERROR" value="0xC0000010" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_FSO_INVALID_FOREST)" symbol="KERBEVT_FSO_INVALID_FOREST" template="T_KERBEVT_FSO_INVALID_FOREST" value="0xC0000011" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_DELEGATED_TGT_EXPIRED)" symbol="KERBEVT_DELEGATED_TGT_EXPIRED" template="T_KERBEVT_DELEGATED_TGT_EXPIRED" value="0x80000012" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_KDC_CERT_MISSING_KDC_EKU)" symbol="KERBEVT_KDC_CERT_MISSING_KDC_EKU" template="T_KERBEVT_KDC_CERT_MISSING_KDC_EKU" value="0x80000013" />
          <event keywords="win:EventlogClassic" message="$(string.event_KERBEVT_KDC_CERT_DOMAIN_NAME_MISMATCH)" symbol="KERBEVT_KDC_CERT_DOMAIN_NAME_MISMATCH" template="T_KERBEVT_KDC_CERT_DOMAIN_NAME_MISMATCH" value="0x80000014" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_GETCERT)" symbol="EVENT_ID_GETCERT" template="T_SCLMSG" value="0x00010005" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_VERIFYCARD)" symbol="EVENT_ID_VERIFYCARD" template="T_SCLMSG" value="0x00010006" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_SIGNMSG)" symbol="EVENT_ID_SIGNMSG" template="T_SCLMSG" value="0x00010007" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_VERIFYMSG)" symbol="EVENT_ID_VERIFYMSG" template="T_SCLMSG" value="0x00010008" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_VERIFYCERT)" symbol="EVENT_ID_VERIFYCERT" template="T_SCLMSG" value="0x00010009" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_ENCMSG)" symbol="EVENT_ID_ENCMSG" template="T_SCLMSG" value="0x0001000A" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_DECMSG)" symbol="EVENT_ID_DECMSG" template="T_SCLMSG" value="0x0001000B" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_BUILDCC)" symbol="EVENT_ID_BUILDCC" template="T_SCLMSG" value="0x0001000C" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_INITIALIZE)" symbol="EVENT_ID_INITIALIZE" template="T_SCLMSG" value="0x0000000D" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_SIGNMSG_NOSC)" symbol="EVENT_ID_SIGNMSG_NOSC" template="T_SCLMSG" value="0x0001000E" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_VERIFYMSG_NOSC)" symbol="EVENT_ID_VERIFYMSG_NOSC" template="T_SCLMSG" value="0x0001000F" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_ENCMSG_NOSC)" symbol="EVENT_ID_ENCMSG_NOSC" template="T_SCLMSG" value="0x00010010" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_DECMSG_NOSC)" symbol="EVENT_ID_DECMSG_NOSC" template="T_SCLMSG" value="0x00010011" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_GETPROVPARAM)" symbol="EVENT_ID_GETPROVPARAM" template="T_SCLMSG" value="0x00010012" />
          <event keywords="win:EventlogClassic" message="$(string.event_EVENT_ID_GENRANDBITS)" symbol="EVENT_ID_GENRANDBITS" template="T_SCLMSG" value="0x00010013" />
          <event channel="Operational" level="win:Error" message="$(string.MissingSpn)" symbol="MissingSpn" template="T_MISSING_SPN" value="100" />
          <event channel="Operational" level="win:Error" message="$(string.DuplicateSpnFound)" symbol="DuplicateSpnFound" template="T_DUPLICATE_SPN_FOUND" value="101" />
          <event channel="Operational" level="win:Error" message="$(string.KdcCertificateValidationFailure)" symbol="KdcCertificateValidationFailure" template="T_KDC_CERTIFICATE_VALIDATION_FAILURE" value="102" />
          <event channel="Operational" level="win:Error" message="$(string.ClientCertificateValidationFailure)" symbol="ClientCertificateValidationFailure" template="T_CLIENT_CERTIFICATE_VALIDATION_FAILURE" value="103" />
          <event channel="Operational" level="win:Error" message="$(string.KdcCertificateMissing)" symbol="KdcCertificateMissing" template="T_KDC_CERTIFICATE_MISSING" value="104" />
          <event channel="Operational" level="win:Error" message="$(string.GmsaGetPasswordsFailure)" symbol="GmsaGetPasswordsFailure" template="T_GMSA_GET_PASSWORDS_FAILURE" value="105" />
          <event channel="Operational" level="win:Error" message="$(string.KdcCertValidationMissingKdcEku)" symbol="KdcCertValidationMissingKdcEku" template="T_KDC_CERT_VALIDATION_MISSING_KDC_EKU" value="106" />
          <event channel="Operational" level="win:Error" message="$(string.KdcCertValidationDomainNameMismatch)" symbol="KdcCertValidationDomainNameMismatch" template="T_KDC_CERT_VALIDATION_DOMAIN_NAME_MISMATCH" value="107" />
          <event channel="Operational" level="win:Error" message="$(string.SendProxyRequestFailure)" symbol="SendProxyRequestFailure" template="T_SEND_PROXY_REQUEST_FAILURE" value="108" />
          <event channel="Operational" level="win:Error" message="$(string.NoAuthProxyCred)" symbol="NoAuthProxyCred" template="T_NO_AUTH_PROXY_CRED" value="109" />
          <event channel="Operational" level="win:Warning" message="$(string.FailureLocatingDc)" symbol="FailureLocatingDc" template="T_FAILURE_LOCATING_DC" value="200" />
          <event channel="Operational" level="win:Informational" message="$(string.DcFound)" symbol="DcFound" template="T_DC_FOUND" value="300" />
          <event channel="Operational" level="win:Informational" message="$(string.CredmanCredentialFound)" symbol="CredmanCredentialFound" template="T_CREDMAN_CREDENTIAL_FOUND" value="301" />
          <event channel="Operational" level="win:Informational" message="$(string.DcNotAccessible)" symbol="DcNotAccessible" template="T_DC_NOT_ACCESSIBLE" value="302" />
          <event channel="Operational" level="win:Informational" message="$(string.GmsaBuildPasswords)" symbol="GmsaBuildPasswords" template="T_GMSA_BUILD_PASSWORDS" value="303" />
        </events>
      </provider>
    </events>
  </instrumentation>
  <migration settingsVersion="0">
    <supportedComponents>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" language="*" name="Microsoft-Windows-Security-Kerberos" processorArchitecture="*" settingsVersionRange="0" />
        <migXml xmlns="">
          <rules context="System">
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\* [*]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
      <supportedComponent>
        <assemblyIdentity name="_" version="1.0.0.0" />
        <supportedComponentIdentity xmlns="urn:schemas-microsoft-com:asm.v3" language="*" name="Microsoft-Windows-Security-Kerberos-DL" processorArchitecture="*" settingsVersionRange="0" />
        <migXml xmlns="">
          <rules context="System">
            <merge script="MigXmlHelper.SourcePriority()">
              <objectSet>
                <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\* [*]</pattern>
              </objectSet>
            </merge>
          </rules>
        </migXml>
      </supportedComponent>
    </supportedComponents>
    <migXml xmlns="">
      <rules context="System">
        <include>
          <objectSet>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\* [*]</pattern>
          </objectSet>
        </include>
        <merge script="MigXmlHelper.SourcePriority()">
          <objectSet>
            <pattern type="Registry">HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters\* [*]</pattern>
          </objectSet>
        </merge>
      </rules>
    </migXml>
  </migration>
  <configuration xmlns="urn:schemas-microsoft-com:asm.v3" xmlns:app="KerberosSchema" xmlns:wcm="http://schemas.microsoft.com/WMIConfig/2002/State">
    <configurationSchema>
      <xsd:schema xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="KerberosSchema" targetNamespace="KerberosSchema">
        <xsd:element name="Kerberos" type="xsd:string" wcm:handler="regtree('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="Parameters" type="xsd:string" wcm:handler="regtree('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="Domains" type="xsd:string" wcm:handler="regtree('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Domains')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="HostToRealm" type="xsd:string" wcm:handler="regtree('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\HostToRealm')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SkewTime" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaxPacketSize" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="KdcWaitTime" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="KdcBackoffTime" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="KdcSendRetries" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LogLevel" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="DefaultEncryptionType" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="FarKdcTimeout" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="NearKdcTimeout" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaxReferralCount" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaxTokenSize" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="SpnCacheTimeout" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="S4UCacheTimeout" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="S4UTicketLifetime" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RetryPDC" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RequestOptions" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="ClientIpAddresses" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="TgtRenewalTime" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="AllowTgtSessionKey" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="KerbDebugLevel" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LogToFile" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="StronglyEncryptDatagram" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="KerbControlLevel" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="CacheS4UTickets" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RealmCacheTimeout" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaximumTickets" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="IterationCount" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MinIterationCount" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaxIterationCount" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="ServiceIterationCount" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="MaxRealmCount" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="CRLTimeoutPeriod" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RejectExts" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="EmitExts" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="LogInvalidCertficate" type="xsd:integer" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
        <xsd:element name="RealmCache" type="xsd:hexBinary" wcm:handler="regkey('HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\Parameters')" wcm:scope="allUsers" wcm:subScope="machineIndependent" />
      </xsd:schema>
    </configurationSchema>
  </configuration>
</assembly>