[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Heimdal kerberos issue after openldap upgrade



On Fri, 2005-10-07 at 19:42 +0200, Love Hörnquist Åstrand wrote:
> Robert Larson <robert@sixthings.com> writes:
> 
> > I try the following:
> > # kadmin -l
> > kadmin> list *
> > kadmin: opening database: ldap_sasl_bind_s: Can't contact LDAP server
> > kadmin: kadm5_get_principals: Wrong database version
> 
> Its the ldap sasl bind to the ldap server that failes. Heimdal can't talk
> to the LDAP serer. Your acl's for the ldap server is correct ? Does your
> ldap server listens to the unix socket ?
> 
> The error "Wrong database version" is just a semi-random error because we
> didn't figure out something better to return.

Earlier this year I tried and failed to get this error to propagate down
the caller stack into a 'no reply' error.  It would be really good if,
when my LDAP server shits itself, Heimdal just 'played dead' rather than
telling my users they don't exist.  If they are lucky, they might then
talk to an Heimdal/LDAP server which is actually up.

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Samba Developer, SuSE Labs, Novell Inc.        http://suse.de
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net

This is a digitally signed message part