[23392] in Kerberos
Re:/usr/lib/gss/gl/mech_krb5.so
daemon@ATHENA.MIT.EDU (coady)
Tue Feb 15 15:59:25 2005
Message-ID: <421255B9.2020201@new.com>
Date: Tue, 15 Feb 2005 15:04:09 -0500
From: coady <coady@new.com>
MIME-Version: 1.0
To: kerberos@mit.edu
In-Reply-To: <200502151708.j1FH8ch7030281@pch.mit.edu>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Do you know where I could find out how to make the SunDS ldap
tools to be configured to use the MIT GSSAPI library?
Any suggestions would be greatly appreciated.
>> Both the LDAP cient and Kerboros server are running Solaris 8.
>> Sun Directory server 5.2.
>>
>> bash-2.03# klist -ef
>> Ticket cache: FILE:/tmp/krb5cc_0
>> Default principal: testadmin/admin@example.com
>>
>> Valid starting Expires Service principal
>> 02/14/05 09:30:57 02/14/05 19:30:57 krbtgt/example.com@example.com
>> renew until 02/14/05 09:30:57, Flags: RI
>> Etype (skey, tkt): Triple DES cbc mode with HMAC/sha1, Triple
>> DES cbc mode with HMAC/sha1
>OK, this means you are using the MIT Kerberos and not the
>Solaris SEAM packages (Solaris 8 SEAM does not recognized 3DES).
>However, your "ldapsearch" command is trying to use the Solaris GSSAPI
>implementation and will not work with MIT.
>If you want to stick with MIT, then you will also need to find LDAP
and >SASL tools that work with MIT and not with the native Solaris
GSSAPI >library or figure out if the SunDS ldap tools can be configured
to use >the MIT GSSAPI library instead of native Solaris.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos