ldap backend issues

2009-01-16 Thread Thomas Mueller
hi i'm playing with debian lenny* and the new kerberos ldap backend. i've stumbled upon a few issues. first, the online documentation**, says to create new ACL's ending with by * none. this disabled the access for all except the two kerberos users. after reading man slapd.access it may be

mod_auth_kerb: gss_accept_sec_context() failed

2009-01-16 Thread Michael Ströder
HI! I'm trying to test mod_auth_kerb-5.4 built with MIT libs 1.6.3 for SPNEGO/Kerberos working with MS AD W2K3SP1. My ultimate goal is to receive a forwardable ticket (env var KRB5CCNAME) and use that for LDAP SASL/GSSAPI bind to AD. The service account in AD is AFAICS properly initialized. The

Re: mod_auth_kerb: gss_accept_sec_context() failed

2009-01-16 Thread Andrew Cobaugh
On Fri, Jan 16, 2009 at 2:58 PM, Michael Ströder mich...@stroeder.com wrote: HI! I'm trying to test mod_auth_kerb-5.4 built with MIT libs 1.6.3 for SPNEGO/Kerberos working with MS AD W2K3SP1. My ultimate goal is to receive a forwardable ticket (env var KRB5CCNAME) and use that for LDAP