[22690] in Kerberos
Re: OpenLDAP -> GSSAPI (SASL) -> KERBEROS V Questions
daemon@ATHENA.MIT.EDU (Gerald (Jerry) Carter)
Tue Oct 19 07:35:00 2004
Message-ID: <4174FA8B.8010003@samba.org>
Date: Tue, 19 Oct 2004 06:29:15 -0500
From: "Gerald (Jerry) Carter" <jerry@samba.org>
MIME-Version: 1.0
To: syslists@vtsystems.com
In-Reply-To: <417432E9.2030201@vtsystems.com>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Matt Joyce wrote:
| What does a principal look like for ldap?
| assuming my realm is WHATEVER.COM
ldap/`hostname`@WHATEVER.COM
| How can I get more verbose error logs without recompiling?
Verbose error logs for the krb libs or for Openldap ?
| And, once i've generated my ldap principal, and his key...
| can I copy the key out of the keytab and chown/chmod it for
| ldap in another directory and expect it to work?
Since (as Sam already said), the service principal
name is ldap/fqdn@REALM, each ldap server will need its
own keytab. It sounds like you are asking if you can
use the same keytab for multiple OpenLDAP installations.
Sorry if i misunderstood.
cheers, jerry
- ---------------------------------------------------------------------
Alleviating the pain of Windows(tm) ------- http://www.samba.org
GnuPG Key ----- http://www.plainjoe.org/gpg_public.asc
"If we're adding to the noise, turn off this song"--Switchfoot (2003)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFBdPqLIR7qMdg1EfYRAp03AJ9xVMKQv3VCklPirUJZg6q1LrhknwCeJ1Ni
99JXjBbZIIifIWb8xIbEioU=
=ML+D
-----END PGP SIGNATURE-----
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos