14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OpenLDAP + SASL + GSSAPI<br />

(OpenLDAP SASL support for Kerberos V)<br />

GSSAPI + OpenLDAP is a delicate combination that can mis-configured in<br />

a variety of ways. Some of the most common mistakes are result in the<br />

following error messages -<br />

ldap_sasl_interactive_bind_s: Local error<br />

The ldap/hostname principle does not exist or the user does not posess a valid<br />

TGT. Be sure to check that the key version numbers are correct, that is they<br />

match tke keys in the LDAP and system keytab files.<br />

ldap_sasl_interactive_bind_s: Can't contact LDAP server<br />

The SSL certificates's CN field may not match the hostname.<br />

gss_acquire_cred: Miscellaneous failure; Permission denied;<br />

This indicates the DSA is having difficulty locating or reading (permissions) the<br />

LDAP keytab file.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!