Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2014-01-31 Thread Bill MacAllister
--On Wednesday, January 29, 2014 10:59:38 AM -0500 Roberto C. Sánchez robe...@connexer.com wrote: On Sun, Mar 24, 2013 at 11:17:22AM -0700, Bill MacAllister wrote: And after doing some more testing, with the correct server this time, I discovered that 2.1.26 does _not_ fix the problem,

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2014-01-29 Thread Roberto C . Sánchez
On Sun, Mar 24, 2013 at 11:17:22AM -0700, Bill MacAllister wrote: And after doing some more testing, with the correct server this time, I discovered that 2.1.26 does _not_ fix the problem, i.e. minssf=1 needs to be specified in the OpenLDAP configuration element olcSaslSecProps. Sorry for

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-25 Thread Bill MacAllister
--On Sunday, March 24, 2013 07:35:27 AM +0100 Ondřej Surý ond...@sury.org wrote: Bill, thanks for investigating this. I'll keep the bug open in case somebody else gets hit by it, and mark it as fixed in 2.1.26 when it hits unstable. O. And after doing some more testing, with the correct

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-25 Thread Ondřej Surý
Bill, thanks for investigating this. I'll keep the bug open in case somebody else gets hit by it, and mark it as fixed in 2.1.26 when it hits unstable. O. On Sun, Mar 24, 2013 at 5:40 AM, Bill MacAllister w...@stanford.edu wrote: --On Thursday, March 21, 2013 04:44:20 PM -0700 Bill

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-23 Thread Bill MacAllister
--On Thursday, March 21, 2013 04:44:20 PM -0700 Bill MacAllister w...@stanford.edu wrote: Yeah, it's almost certainly an upstream bug. Ah, I see that Cyrus SASL has a Bugzilla and everything these days. Once I complete testing today I will file the bug. And I confirmed that if I use TLS

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-21 Thread Ondřej Surý
It might be related to http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665476 As a first thing I would suggest to recompile Java bindings. Also when you said: We do not see this problem on our squeeze systems using version 2.1.23.dfsg1-8 of libsasl2-modules-gssapi-mit. We do see the same

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-21 Thread Russ Allbery
(Bill and I work in the same group.) Ondřej Surý ond...@sury.org writes: It might be related to http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665476 This bug is about the ABI of the Cyrus SASL libraries. In the problem we're having, the libraries are being loaded by slapd just fine, and

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-21 Thread Ondřej Surý
On Thu, Mar 21, 2013 at 5:26 PM, Russ Allbery r...@debian.org wrote: (Bill and I work in the same group.) Ondřej Surý ond...@sury.org writes: It might be related to http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665476 This bug is about the ABI of the Cyrus SASL libraries. In the

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-21 Thread Russ Allbery
Ondřej Surý ond...@sury.org writes: On second read – I have understood this as this doesn't work with heimdal libraries both in squeeze and wheezy. So to clarify this – does it work when you switch from mit to heimdal on squeeze? Basically, it works on squeeze and doesn't work on wheezy,

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-21 Thread Bill MacAllister
--On Thursday, March 21, 2013 09:51:45 AM -0700 Russ Allbery r...@debian.org wrote: Ondřej Surý ond...@sury.org writes: On second read – I have understood this as this doesn't work with heimdal libraries both in squeeze and wheezy. So to clarify this – does it work when you switch from mit

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-21 Thread Bill MacAllister
--On Thursday, March 21, 2013 10:02:10 AM -0700 Bill MacAllister w...@stanford.edu wrote: --On Thursday, March 21, 2013 09:51:45 AM -0700 Russ Allbery r...@debian.org wrote: Ondřej Surý ond...@sury.org writes: Basically you have much deeper knowledge of SASL and Kerberos internals than

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-18 Thread Bill MacAllister
--On Saturday, March 16, 2013 07:03:38 PM -0500 Dan White dwh...@olp.net wrote: On 03/15/13 01:47 -0700, Bill MacAllister wrote: Package: libsasl2-modules-gssapi-mit Version: 2.1.25.dfsg1-6 Severity: important Dear Maintainer, We are starting the process of upgrading our LDAP service to

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-16 Thread Dan White
On 03/15/13 01:47 -0700, Bill MacAllister wrote: Package: libsasl2-modules-gssapi-mit Version: 2.1.25.dfsg1-6 Severity: important Dear Maintainer, We are starting the process of upgrading our LDAP service to OpenLDAP 2.4.34 on wheezy. None of the Java applications that we have tested can

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-16 Thread Russ Allbery
Dan White dwh...@olp.net writes: On 03/15/13 01:47 -0700, Bill MacAllister wrote: We are starting the process of upgrading our LDAP service to OpenLDAP 2.4.34 on wheezy. None of the Java applications that we have tested can connect to the LDAP server using GSSAPI. Can you reproduce this

Bug#703113: libsasl2-modules-gssapi-mit: Java client GSSAPI connections to OpenLDAP fail

2013-03-15 Thread Bill MacAllister
Package: libsasl2-modules-gssapi-mit Version: 2.1.25.dfsg1-6 Severity: important Dear Maintainer, We are starting the process of upgrading our LDAP service to OpenLDAP 2.4.34 on wheezy. None of the Java applications that we have tested can connect to the LDAP server using GSSAPI. In the server