--On Thursday, January 16, 2020 9:03 PM +0000 Prentice Bisbal
One of my coworkers just noticed that replication is broken between
primary and secondary LDAP servers. It appears to have been broken for
about 1 week now. Nothing has changed relative to the LDAP configuration
on either of our servers, so this is an odd thing to suddenly happen.
When I look at the consumer with some debugging on, I see these messages
(/usr/sbin/slapd -d 1638 was used to get these messages):
It looks like the consumer
host/voltron-b.pppl.gov,cn=pppl.gov,cn=gssapi,cn=auth,is being rejected
as not being authorized, but this has been working for years w/o issue.
Any idea what has changed and how I may fix it?
Well, the error came from cyrus-sasl rather than OpenLDAP. This would
indicate to me that the not authorized came from the KDC. Have you checked
to ensure the keys in the keytab file haven't expired inside the KDC?
Packaged, certified, and supported LDAP solutions powered by OpenLDAP: