logo       

Re: libnss-ldap authenticate with host keytab?: msg#00023

ldap.padl.nss

Subject: Re: libnss-ldap authenticate with host keytab?


>> 3) You can then edit ldap.conf to use sasl.
>
>This is actually the point that is tripping me up the most. What is the
>identifier that should be used with the sasl_authid configuration directive?
>I've tried host/host.domain to use the default domain as well as appending
>the realm explicitly. Is there another method to enable SASL? That is all I
>was able to find documented in the code and nss_ldap.5

Generally the following works for me (with KCM):

sasl_auth_id CLIENT$
use_sasl on
krb5_ccname KCM:SYSTEM
SASL_MECH GSSAPI

-- Luke

--



<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise