Posted by bmontgom on Sat 22 Oct 2005 at 17:32
Has anyone been able to implement a single sign on using the OpenLDAP and Kerberos packages from Debian? I've been able to get OpenLDAP and Kerberos to work independently, but I can't get them to work together.
I've been using the instructions at www.bayour.com, but they seem a little out of date.
The instructions on the Debian wiki are incomplete. Has anyone been able to get this to work?
neo:~# ldapsearch -Y gssapi
SASL/GSSAPI authentication started
ldap_sasl_interactive_bind_s: Local error (-2)
additional info: SASL(-1): generic failure: GSSAPI Error: An invalid name was supplied (Cannot determine realm for numeric host address)
[ Parent ]
"Cannot determine realm" makes it sound like you might have a broken /etc/krb5.conf on your client, or a poorly specified default LDAP HOST or SASL_REALM. can you give more details about your setup? The relevant details might include:
[ Parent ]
[ Parent ]
[ Parent ]
[ Parent ]
[ Parent ]
[ Parent ]
I've got LDAP/Kerberos working on a single machine, so what I have may not work in a larger situation, but I'd be happy to give you any pointers.
[ Parent ]