https://bugs.openldap.org/show_bug.cgi?id=9547
--- Comment #2 from robert.wilson1717@gmail.com --- (In reply to Michael Ströder from comment #1)
On 5/5/21 2:39 PM, openldap-its@openldap.org wrote:
causing a mismatch between the SPN in the client "ldap/adlds.my.domain" and the one registered in AD "ldap/adlds.my.domain:50000"
I have some doubts that it's correct to add the port number to servicePrincipalName in MS AD. Did you try without?
Without is what OpenLDAP currently performs.
See MS Docs regarding ADLDS SPNs: https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-drsr/3a6c821...