Re: Preauth error ldap heimdal kerberos

Dan White <[email protected]> Mon, 22 Mar 2010 11:20:31 -0500
Newsgroups gmane.network.openldap.general
Message-ID <[email protected]>
On 22/03/10 18:09 +0200, Μανόλης Βλαχάκης wrote:
>finally ldap log works fine...but from the log i get is that none of the
>requests are being responded
>with data...:(for example the first one ...)
>* acl_mask: access to entry
>"krb5PrincipalName=kadmin/[email protected],ou=kerberos,dc=teipir,dc=gr",
>attr "uid" requested

I don't know.

>but i still have the problem :
>
>SASL/GSSAPI authentication started
>ldap_sasl_interactive_bind_s: Insufficient access (50)
>        additional info: SASL(-14): authorization failure: not authorized

I would guess that there is a problem with your proxy authorization
configuration.

Does 'ldapwhoami' return a string which your authz-regexp is matching?

-- 
Dan White