Re: [opensuse] Kerberos Schema unknown by LDAP server



On Sonntag, 29. Juni 2008, Husam Senussi wrote:
Hi.

I'm trying to setup kerberos to use LDAP as backend but I'm getting
the "Kerberos Schema unknown by LDAP server",
I have included the schema to my configuration file and restarted the
server.

slapd.conf:

include /etc/openldap/schema/core.schema
include /etc/openldap/schema/cosine.schema
include /etc/openldap/schema/inetorgperson.schema
include /etc/openldap/schema/rfc2307bis.schema
include /etc/openldap/schema/yast.schema
include /etc/openldap/schema/dnszone.schema
include /etc/openldap/schema/suse-mailserver.schema
include /etc/openldap/schema/krb5-kdc.schema

LDAP server is up and running and I can connected to it.

krb5-kdc.schema file was included in the default installation I had
to get from
http://www.bayour.com/openldap/schemas/krb5-kdc.schema.
I guess you are using the wrong schema. In case you are trying to setup
a MIT Kerberos Server, have you tried the Kerberos Schema that ships
with krb5-plugin-kdb-ldap RPM
(/usr/share/doc/packages/krb5/kerberos.schema)?

--
Ralf
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: Authenticating LDAP connection with current windows users credentials?
    ... setup and theory behind an ldap ... The Kerberos only works with ADS right now but that is sufficient for your situation. ... when the user has logged in interactively and therefore has a valid Kerberos ticket cached in Windows logon credential cache. ... CallbackHandler callbackHandler = new KerbCallback; ...
    (comp.lang.java.programmer)
  • Re: Anyone has an apache running with mod_auth_kerb AND mod_auth_ldap?
    ... (Specified realm `persona.de' not allowed by configuration) ... I recommend steering this thread back onto the kerberos mailing list. ... So what you're saying is that users do not know their userPrincipalName ... You could split the name and do an LDAP search on sAMAccountName=abaker ...
    (comp.protocols.kerberos)
  • Re: Kerberos Confusion / Design Questions
    ... > I'm planning on deploying Sun-Kerberos with LDAP I have a few design ... > server via gssapi-keyex SSO and other servers can log back into my ... > that is puzzling me is how to handle Kerberos access, ... > authentication will basically be provided through LDAP at this point ...
    (comp.protocols.kerberos)
  • LDAP+Kerberos in Solaris 8
    ... LDAP & Kerberos clients: ... error No account present for user ... # Authentication management ...
    (SunManagers)
  • Re: LDAP be killing me. I need a good step by step
    ... very notion when I first started mucking with LDAP. ... Is there some reason that there isn't a standard schema shipped with the ... I would venture to guess that Kontact like Evolution and all ... other address book clients each has their own schema. ...
    (Fedora)