Re: Kerberos through loadbalancer

2022-05-27 Thread Stefan Kania
Hi Russ Am 20.05.22 um 18:45 schrieb Russ Allbery: > Stefan Kania writes: > >> we have 4 ldap-provider ldap1.example.net to ldap4.example.net. We >> securing the replication via kerberos, everything works fine between the >> providers. But now we want to set up some consumers. Between the >> pro

Re: Kerberos through loadbalancer

2022-05-20 Thread Russ Allbery
Stefan Kania writes: > we have 4 ldap-provider ldap1.example.net to ldap4.example.net. We > securing the replication via kerberos, everything works fine between the > providers. But now we want to set up some consumers. Between the > providers and the consumers a loadbalancer is located, so the c

Re: Kerberos through loadbalancer

2022-05-20 Thread Stefan Kania
Here the messages we get using ldapsearch on one of the consumers: --- ldapsearch -H ldaps://ldap.example.net SASL/GSSAPI authentication started ldap_sasl_interactive_bind: Invalid credentials (49) additional info: SASL(-13): authentication failure: GSSAPI Failure: gss_accept_sec_co