Re: GSSAPI authentication between 1.2.10 and 1.2.11

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Are you using ldapsearch?

Anyway, double check these settings:

[1]  /etc/sysconfig/dirsrv-INSTANCE

        make sure that KRB5_KTNAME points to the correct keytab file!!

[2] Check your DS mappings in the dse.ldif (you can only edit this file, when the server is stopped)

Make sure the nsSaslMapBaseDNTemplate attr points to your correct DIT name(dc=company,dc=com, etc)

    dn: cn=Kerberos uid mapping,cn=mapping,cn=sasl,cn=config
    changetype: modify
    replace: nsSaslMapBaseDNTemplate
    nsSaslMapBaseDNTemplate: o=testsasl.com

    dn: cn=rfc 2829 dn syntax,cn=mapping,cn=sasl,cn=config
    changetype: modify
    replace: nsSaslMapBaseDNTemplate
    nsSaslMapBaseDNTemplate: o=testsasl.com

    dn: cn=rfc 2829 u syntax,cn=mapping,cn=sasl,cn=config
    changetype: modify
    replace: nsSaslMapBaseDNTemplate
    nsSaslMapBaseDNTemplate: o=testsasl.com

    dn: cn=uid mapping,cn=mapping,cn=sasl,cn=config
    changetype: modify
    replace: nsSaslMapBaseDNTemplate
    nsSaslMapBaseDNTemplate: o=testsasl.com

[3]  Make sure /etc/krb5.conf is configured correctly

[4] If this fails, stop slapd, edit dse.ldif and add "nsslapd-errorlog-level: 1" to the cn=config entry

-> then reproduce the error, and send me the error log. Then you can unset that attribute, as it will significantly degrade performance.

There are a lot of other factors, like are your keytabs correct? Is DNS correctly working? Etc.

Mark

On 05/30/2012 06:20 PM, Edward Z. Yang wrote:
We haven't been able to get anything more specific than err=49.

Edward

Excerpts from Mark Reynolds's message of Wed May 30 16:30:00 -0400 2012:
Edward,

What is the error you are getting?

Mark

On 05/30/2012 12:54 AM, Edward Z. Yang wrote:
Hello all,

We are trying to setup GSSAPI SASL authentication using Kerberos keytabs
between 389-ds 1.2.10.6 (on Fedora 15) and 1.2.11.4 (on Fedora 17).
However, we are getting an unspecified GSSAPI error.  Are there
any known bugs / changes that could possible cause this to happen?

Edward
--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users

--
Mark Reynolds
Senior Software Engineer
Red Hat, Inc
mreynolds@xxxxxxxxxx

--
389 users mailing list
389-users@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/389-users



[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux