14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OpenLDAP + SASL + GSSAPI<br />

(OpenLDAP SASL support for Kerberos V)<br />

The OpenLDAP service must be able to locate the keytab it is intended to<br />

use, this is best accomplished by setting the KRB5_KTN<strong>AM</strong>E<br />

environment variable in the script that starts the LDAP service.<br />

export KRB5_KTN<strong>AM</strong>E="FILE:/etc/openldap/ldap.keytab"<br />

Instruct slapd to use the GSSAPI module by defining the following SASL<br />

directives in /etc/openldap/slapd.conf -<br />

Keytab file<br />

srvtab /etc/openldap/ldap.keytab<br />

sasl-realm WHITEMICE.ORG<br />

Kerberos Realm<br />

sasl-host estate1.whitemice.org<br />

KDC<br />

For more information see:<br />

http://www.bayour.com/LDAPv3-HOWTO.html

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!