Re: kdb5_ldap_util fails, no idea why

2016-11-08 Thread t Seeger
Hello Lars, I corrected a little bug in my script so please use the new version https://wp.tntnet.eu/?p=112 . The bug is only a problem in a multimaster setup, cause the keytab is not updated correctly. - Thorsten Von meinem iPhone gesendet > Am 08.11.2016 um 08:58 schrieb t Seeger

Re: kdb5_ldap_util fails, no idea why

2016-11-08 Thread t Seeger
Hello, You can add the principals under the users cn this is possible too. You just need to specify the dn of the user, while adding it. For GSSAPI I use the olcAuthzRegexp to transfer to the ldap objects. My userPassword attribute looks like: {SASL}username@REALM. -Thorsten Von meinem

Re: kdb5_ldap_util fails, no idea why

2016-11-08 Thread Dr. Lars Hanke
ldap_kerberos_container_dn = cn=KERBEROS,dc=microsult,dc=de made it succeed.This is however not mentioned in the HOWTO.From the documentation of -subtree I thought that the Principals would somehow be stored with the User and Machine entries, i.e. not in a seperate tree. So the idea for GSSAPI

Re: kdb5_ldap_util fails, no idea why

2016-11-08 Thread t Seeger
Hello, did you create the /etc/krb5kdc/kdc.conf file? The Kerberos Containern dn is setup there (ldap_kerberos_container_dn). And you need to use 'cn' for the container this change some versions ago. [dbmodules] LDAP = { db_library = kldap ldap_kerberos_container_dn =

Re: kdb5_ldap_util fails, no idea why

2016-11-07 Thread Dr. Lars Hanke
Am 07.11.2016 um 15:06 schrieb Todd Grayson: > From that error message you need to provide the schema file for the > kerebros ldap objects to your directory instance. Can we assume you > followed top down the instructions from here? > > https://help.ubuntu.com/lts/serverguide/kerberos-ldap.html

Re: kdb5_ldap_util fails, no idea why

2016-11-07 Thread Todd Grayson
>From that error message you need to provide the schema file for the kerebros ldap objects to your directory instance. Can we assume you followed top down the instructions from here? https://help.ubuntu.com/lts/serverguide/kerberos-ldap.html On Sat, Nov 5, 2016 at 3:03 PM, Dr. Lars Hanke

Re: kdb5_ldap_util fails, no idea why

2016-11-07 Thread Dr. Lars Hanke
I had a brief look at the scripts - well, the idea to understand the relevant parts and reproduce on my own seems laborous at least. I guess I'll set up a VM, install your system and try to understand, what it did. Thank you, - lars. Am 06.11.2016 um 11:25 schrieb t Seeger: > Hello, > > I

Re: kdb5_ldap_util fails, no idea why

2016-11-06 Thread t Seeger
Hello, I made a installer script to setup a Kerberos server with ldap backend. It is for ubuntu or debian only. The script is not perfect and for testing, but should guide you in the right direction. You can find it under: https://wp.tntnet.eu/?p=112 Thorsten Von meinem iPhone gesendet > Am

kdb5_ldap_util fails, no idea why

2016-11-05 Thread Dr. Lars Hanke
I'm currently setting up a new KDC for a new domain. I also have a shiny new LDAP. I want Kerberos to use LDAP as backend. LDAP connectivity is fine, there is no specific data in it yet. Trying to create the Kerberos container, I get the following error: kdb5_ldap_util -D