LDAP with Kerberos authentification

From: Eugen Wintersberger (eugen.wintersberger_at_jku.at)
Date: 06/30/05

  • Next message: Brian Nelson: "Re: No security updates for sarge ?"
    To: debian-user@lists.debian.org
    Date: Thu, 30 Jun 2005 12:09:44 +0200
    
    

    Hi there
     I have a problem with slapd using Kerberos V (GSSAPI) authentification
    on Debian 3.1 Sarge. The Kerberos configuration seems to be ok since
    cyrus imap daemon uses it without any problems.

    I also added the appropriate principals to my Kerberos database and to
    the krb5.keytab file:

     ldap/hubbard.hlphys.uni-linz.ac.at@HLPHYS.UNI-LINZ.AC.AT
     ldap/localhost@HLPHYS.UNI-LINZ.AC.AT

    After getting my TGT with

    > kinit admin

    I tried a simple

    > ldapwhoami -h hubbard.hlphys.uni-linz.ac.at

    and got the following error message

    SASL/GSSAPI authentication started
    ldap_sasl_interactive_bind_s: Internal (implementation specific) error (80)
            additional info: SASL(-1): generic failure: GSSAPI Error: Miscellaneous failure (No principal in keytab matches desired name)

    I got a similar error with cyrus imapd before I changed the "servername" variable in imapd.conf to the
    hostname.
    Has anyone an idea what I'm doing wrong?

    thanks

      Eugen

    -- 
    Eugen Wintersberger <eugen.wintersberger@gmx.net>
    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Brian Nelson: "Re: No security updates for sarge ?"

    Relevant Pages

    • Re: SQL7 servers integration in Active Direcory 2003
      ... AD uses Kerberos by default but will use NTLM is Kerberos fails. ... need to be aware of if you were doing any server to server communications. ... SQL Agent has an issue validating those credentials. ... Directory i want to kow if we make an on place migration if the NT authentification will be ok when we ll have AD 2003. ...
      (microsoft.public.sqlserver.server)
    • Re: LDAP with Kerberos authentification
      ... On Thursday 30 June 2005 06:09 am, Eugen Wintersberger wrote: ... > I have a problem with slapd using Kerberos V authentification ... The Kerberos configuration seems to be ok since ... that slapd can read the keytab that contains everything relevant to it, ...
      (Debian-User)
    • JAAS
      ... I have been trying to implement authentification of AD users with kerberos ... im my web app. ... I have setup my realm, kdc, krb5.conf and all the necessary JAAS option as ... For the HTTP authentification, do I have to do some kind of Negotiation ...
      (comp.lang.java.programmer)
    • Heimdal + OpenLDAP
      ... LDAP abzulegen und die Authorisierung an Kerberos auszulagern. ... # Kerberos Configuration ... SASL/GSSAPI authentication started ... Die Applikationen müsten dann nicht kerberisiert ...
      (de.comp.os.unix.misc)