[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Problems access MS Active Directory from OpenLDAP 2.1.2



Today at 7:26am, Anthony Brock wrote:

> The -x option is incompatible with Kerberos authentication. So, when
> attempted, I see the following:
>
> # ldapsearch -x -I -H ldap://exsrv.test1.georgefox.com/ -b
> "dc=test1,dc=georgefox,dc=com" objectclass=user
> ldapsearch: incompatible previous authentication choice
> #

Be clear... you have asked for (-x) "Use simple authentication instead
of SASL" and (-I) "Enable SASL Interactive mode."  --- of course they're
incompatible....  But it has nothing to do with Kerberos at all.

Why are you trying to use GSSAPI (in your original post) and simple
binding now and always requesting Interactive SASL???  Try it without
the -I.

I think you should also read the ldapsearch manpage and the howto at
http://www.bayour.com/LDAPv3-HOWTO.html -- just my !HO.

-- 
Frank Swasey                    | http://www.uvm.edu/~fcs
Systems Programmer              | Always remember: You are UNIQUE,
University of Vermont           |    just like everyone else.
                    === God Bless Us All ===