I found my mistakes...

In slapd.conf I forgot:

sasl-realm      va.elysium-os.nl
sasl-host       eosdeb40.va.elysium-os.nl

And the ACL has to start with uid= not cn=

access to *
  by dn="uid=emgadmin/admin,cn=va.elysium-os.nl,cn=gssapi,cn=auth" write
  by * read

This has the result

eosdeb40:~/ldap# ldapadd -H ldap:// -f
SASL/GSSAPI authentication started
SASL username: emgadmin/[EMAIL PROTECTED]
SASL installing layers
adding new entry "ou=people,dc=va,dc=elysium-os,dc=nl"

I still find it strange that the SASL authentication looked just fine when
it all went totally wrong.

Thanks anyway for the help

with kind regards,

You are currently subscribed to [EMAIL PROTECTED] as: [EMAIL PROTECTED]
To unsubscribe send email to [EMAIL PROTECTED] with the word UNSUBSCRIBE as the 
SUBJECT of the message.

Reply via email to