On 01/21/10 01:09 PM, Henry B. Hotz wrote: > Perhaps a compromise solution would be to use SASL/Kerberos over TLS? If > you're using the SASL security layer that's silly and inefficient, but it > might be easier to deal with. >
Or depending on the customer's policy; temporarily turn off LDAP signing, join the client to the domain, and turn LDAP signing back on. -- Shawn.