>Thanks for the hint. I did read that it would not be supported over SSL the competing port would be a valid reason. I did get the mapping pieces completed but had some difficulty understanding the REALMS docs. http://www.redhat.com/docs/manuals/dir-server/ag/7.1/ssl.html#1083165 >The docs state that GSS-API must be enabled as a SASL mechanism in the Directory to make this work, but it does not state how if this is the default or if not how to enable GSS-API. The Realms section reads as if I have to change the DN of all users in the directory to be under cn=gssapi,cn=auth and therefore the confusion. > > That 'realms' section in the doc is just plain wrong. In fact I'm not really sure how it got in there. Please disregard it altogether.