[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Cross Realm HELP
- To: firstname.lastname@example.org
- Subject: Re: Cross Realm HELP
- From: Jeremiah Martell <email@example.com>
- Date: Tue, 11 Oct 2005 15:28:58 -0400
- DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=XEQioBv9LSs8nwEB75H70dv1BPlPrlDIgIz1/Q+g6NXVZlE9vlqVZChiiBBxm4hOtgXeSPKGWfngaXP9W89qhat8G7LNRjz5toaBsOHj4hKYIJuHtrbPfJ31vo0dVTwfhGcqcIWycnP357JcuBFSQsPNS+cu73db44PF0I5HLBU=
- In-Reply-To: <firstname.lastname@example.org>
- References: <email@example.com> <20050921025701.GA15992@dsl092-173-085.wdc2.dsl.speakeasy.net> <firstname.lastname@example.org> <20050922141813.GA20580@dsl092-173-085.wdc2.dsl.speakeasy.net> <email@example.com> <20050924230731.GA28302@dsl092-173-085.wdc2.dsl.speakeasy.net> <firstname.lastname@example.org>
- Sender: email@example.com
I can kinit to realm A, and then use ldapsearch -Y GSSAPI to access the ldap directory in realm A.
I cannot kinit to realm B, and then use ldapsearch -Y GSSAPI to access
the ldap directory in realm A. (Even though there's a trust between the
realms B and A)
However, I can first kinit to B, use kvno to manually get a ticket for
the ldap directory in realm A (kvno ldap/domainA@realmA), and then use
ldapsearch -Y GSSAPI to access the ldap directory in realm A.
Another nugget of information is that the ldapsearch that comes
standard with my linux box (Fedora) works fine. I kinit to realm B,
ldapsearch on realm A, and it all works. But when I create my own
ldapsearch with (heimdal, cyrus-sasl, openldap) I run into the above
problem. I can't think of what I could be doing wrong though.
Buck Huppmann <firstname.lastname@example.org
On Fri, Sep 23, 2005 at 11:13:44AM -0400, Jeremiah Martell wrote:
> Thanks again.
> I will definitely try what you suggested. I do have a copy of kinit and
> klist on my Linux box. However, I noticed that I can't find the kinit and
> klist that is built by heimdal. I've looked in the install directory I gave
> heimdal's configure, but it's not there. Am I missing something?
sorry. can't help you there, unless you have a log of your build
process and config.log and config.status