openldap-sasl fails after 8.1 upgrade

Leon Meßner l.messner at
Wed Aug 25 16:20:55 UTC 2010


after binary upgrading to freebsd8.1 from 7.2 i encounter an error
with openldap24, cyrus-sasl2 and kerberos:

# ldapsearch uid=whatever
SASL/GSSAPI authentication started
ldap_sasl_interactive_bind_s: Other (e.g., implementation specific)
error (80)
        additional info: SASL(-1): generic failure: GSSAPI Error:  No
credentials were supplied, or the credentials were unavailable or
inaccessible. (unknown mech-code 0 for mech unknown)

Simple binding to the ldap server does work. The KDC behind this is
still on kerberos 0.6.3 (FreeBSD7.3) and there have been reported
Problems with such a setup, but as i can login through ssh and kerberos
i suppose these [1] don't apply here (also already tested the proposed

If anybody got any insight please share.

Thanks in Advance,


