Re: Problems access MS Active Directory from OpenLDAP 2.1.2

Today at 7:26am, Anthony Brock wrote:

> The -x option is incompatible with Kerberos authentication. So, when
> attempted, I see the following:
> # ldapsearch -x -I -H ldap://exsrv.test1.georgefox.com/ -b
> "dc=test1,dc=georgefox,dc=com" objectclass=user
> ldapsearch: incompatible previous authentication choice
> #

Be clear... you have asked for (-x) "Use simple authentication instead
of SASL" and (-I) "Enable SASL Interactive mode."  --- of course they're
incompatible....  But it has nothing to do with Kerberos at all.

Why are you trying to use GSSAPI (in your original post) and simple
binding now and always requesting Interactive SASL???  Try it without
the -I.

I think you should also read the ldapsearch manpage and the howto at
http://www.bayour.com/LDAPv3-HOWTO.html -- just my !HO.

