Re: Unable to BIND with SASL(GSSAPI). Getting "AcceptSecurityContext error, data 7a, vece" error consistently

Rich Megginson <[email protected]>
Newsgroups gmane.comp.mozilla.devel.directory
Message-ID <[email protected]>
Kashif Ali Siddiqui wrote:
> Hi All,
> 
> I am the same guy from the following posting
> http://groups.google.com/group/mozilla.dev.tech.ldap/browse_thread/thread/cd73867a6a56eabf?tvc=2
> 
> I am using Microsoft Server2003 SP1 Active Directory and want to do
> LDAP_SASL_BIND using GSSAPI mechanism (Kerberos5). I have setup an
> instance for Microsoft Server2003 and a Linux client machine with
> Mozilla LDAP 6.0.4 with Cyrus SASL libraries. I have a client code
> ready (code pasted in the above posting) and I am not able to get
> through the BIND call. It is consistently giving me error
> 
> Bind Error [49]: Invalid credentials
> Bind Error [49]: additional info: 8009030B: LdapErr: DSID-0C09043E,
> comment: AcceptSecurityContext error, data 7a, vece
> 
> By the way, I have successfully kinit the user credentials and they
> are fetched in the cache. Also after failed attempts of
> ldap_sasl_interactive_bind (ended with above error) I am still getting
> the service ticket as shown when I do klist.
> 
> In the previous posting, I was successfully done the bind, but
> unfortunately I lost the Server2003 instance along with the
> configurations I made on it. Now I have recreated the same
> environment, using the same client, but it is giving me the error.
> 
> Kindly help me in this. State all the configuration that I need on my
> Server2003 for kerberos access or any other requirements that I need
> to take care off. If there are some links to the sites that state
> these configuration kindly state them.

I don't know. I've never tried that.  I thought Windows used some 
non-standard Kerberos extensions.  Please let us know if you can figure 
out how you got it to work before.

> 
> Any help will be appreciated.
> Thanks
> 
> Kashif Ali Siddiqui
> Tech Lead Folio3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.