On Mon, 2008-02-18 at 14:36 -0800, Russ Allbery wrote:
No, the correct way of supporting Kerberos is by way of SASL, which OpenLDAP continues to support. Via SASL you can negotiate GSSAPI authentication using Kerberos v5.
/me smacks forehead.
Doh! Of course. I seem to have it working now. Unfortunately it doesn't seem many clients (i.e. neither evolution nor GQ) support the use of the GSSAPI SASL method AFAICT. :-(
Thanx much!
b.