LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 05-04-2009, 02:17 PM   #1
p1111a
LQ Newbie
 
Registered: May 2009
Location: New York, NY
Distribution: RHEL
Posts: 3

Rep: Reputation: 0
using ldapsearch gettting Invalid credentials (49) error


Hello all,

I have been trying to get this to work for sometime now and need some suggestions, please.

I have a RHEL 5 environment (under VMware) and have been able to get kerberos and ldap to work correctly using simple authentication (-x). However, when I use gssapi via the ldapsearch command I get the following error:

ldapsearch
SASL/GSSAPI authentication started
ldap_sasl_interactive_bind_s: Invalid credentials (49)
additional info: SASL(-13): authentication failure: GSSAPI Failure: gss_accept_sec_context

I don't see anything in the kerberos log when I run the ldapsearch command, which I assume indicates a problem with the ldap server (or other).
Please let me know if there is anymore information I can provide.

Thanks in advance.
 
Old 05-05-2009, 12:59 PM   #2
archangel_617b
Member
 
Registered: Sep 2003
Location: GMT -08:00
Distribution: Ubuntu, RHEL/CentOS, Fedora
Posts: 234

Rep: Reputation: 42
I can't say I can offer too much help, but since nobody else has responded, I'll put in my two cents...

Can you show what tickets you've got from klist? Have you got all your service principals etc setup?

- Arch
 
Old 05-05-2009, 02:25 PM   #3
p1111a
LQ Newbie
 
Registered: May 2009
Location: New York, NY
Distribution: RHEL
Posts: 3

Original Poster
Rep: Reputation: 0
Thank you for the reply. I do have a tgt from the kerberos server. And (I think) I have the appropriate service principal. Here you go:

[root@gateway1-vm openldap]# klist -5
Ticket cache: FILE:/tmp/krb5cc_0
Default principal: testldap1@SYSENGLAB.NET

Valid starting Expires Service principal
05/05/09 12:13:34 05/06/09 12:13:34 krbtgt/SYSENGLAB.NET@SYSENGLAB.NET
05/05/09 12:13:51 05/06/09 12:13:34 ldap/gateway1-vm

Thanks again.
 
Old 05-15-2009, 05:44 PM   #4
p1111a
LQ Newbie
 
Registered: May 2009
Location: New York, NY
Distribution: RHEL
Posts: 3

Original Poster
Rep: Reputation: 0
I have figured out the problem. I decided to go through my entire DNS setup and changed the resolve address to return FQDN for each host. After this I was able to run the command (ldapsearch) and do what I initially intended....which was to be able to SSO (single sign on) using a completely RHEL 5 environment.
The issue here is that my company (for what ever reason) at one point (before I took over the ldap/kerberos administration) decided to use short names for the reverse lookups. This worked for a long time until we decided to go with RHEL 5 and SSO stopped working so I was forced to revisit the entire ldap/kerberos envirnment.

Thanks for the replies.... - PJM
 
  


Reply

Tags
ldapsearch


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ldap_bind: Invalid credentials (49) pdrobe Linux - General 12 09-13-2012 02:41 AM
ldap_bind: Invalid credentials (49) soni_silver17 Linux - Server 1 01-24-2009 01:47 PM
ldap invalid credentials finsh Linux - Server 4 12-12-2007 12:11 PM
LDAP_BIND: Invalid Credentials rupesh_pulikool Linux - Software 0 02-01-2005 01:27 PM
ldap invalid credentials johond Linux - Networking 1 12-14-2004 04:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:09 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration