The issue appears to be related to there being not 'base dn' being
specified. Try with -b 'dc=samba4,dc=kzsdabas,dc=hu'.
This behaviour may not match windows - if you can test against that,
please let us know the difference and we can sort it out. Base DN
specification and defaults changed mid last year.
> and
>
> # ldapwhoami -H ldap://samba4.kzsdabas.hu -Y GSSAPI
> SASL/GSSAPI authentication started
> SASL username: Admini...@KZSDABAS.HU
> SASL SSF: 56
> SASL data security layer installed.
> ldap_parse_result: Protocol error (2)
> additional info: Extended Operation(1.3.6.1.4.1.4203.1.11.3) not
> supported
> Result: Protocol error (2)
> Additional info: Extended Operation(1.3.6.1.4.1.4203.1.11.3) not supported
>
> So the question is does the Samba4 LDAP server support SASL/GSSAPI based
> binding?
We support SASL/GSSAPI. We do not (patches very welcome) currently
support the extended operation ldapwhoami uses.
Andrew Bartlett
--
Andrew Bartlett http://samba.org/~abartlet/
Authentication Developer, Samba Team http://samba.org
Specifying the base dn was the problem, but that still doesn't explain
(although suggest that the problem lies with nslcd itself) the original
problem.
>> and
>>
>> # ldapwhoami -H ldap://samba4.kzsdabas.hu -Y GSSAPI
>> SASL/GSSAPI authentication started
>> SASL username: Admini...@KZSDABAS.HU
>> SASL SSF: 56
>> SASL data security layer installed.
>> ldap_parse_result: Protocol error (2)
>> additional info: Extended Operation(1.3.6.1.4.1.4203.1.11.3) not
>> supported
>> Result: Protocol error (2)
>> Additional info: Extended Operation(1.3.6.1.4.1.4203.1.11.3) not supported
>>
>> So the question is does the Samba4 LDAP server support SASL/GSSAPI based
>> binding?
> We support SASL/GSSAPI. We do not (patches very welcome) currently
> support the extended operation ldapwhoami uses.
>
> Andrew Bartlett
>
Cheers
Geza