Troubleshooting

Troubleshooting Kerberos

Table 11-3

Troubleshooting Scenarios for your LDAP-based Kerberos

 

server (Continued)

 

 

 

 

 

 

 

Scenario

Cause

Troubleshooting

 

 

 

Tips

 

 

 

 

 

LDAP database is

An attempt to modify

Edit the Kerberos

 

read-only

the Kerberos entry

configuration file,

 

 

failed as the

krb5_ldap.conf, to

 

 

Directory server

specify a directory

 

 

entry is read-only.

server that can be

 

 

 

updated and restart all

 

 

 

Kerberos server

 

 

 

applications

 

 

 

 

 

Insufficient access

The proxy user does

Change the

 

on LDAP

not have sufficient

configuration on the

 

 

privileges to add,

Directory server to

 

 

modify, delete, and

allow add, modify,

 

 

search for entries on

delete, and search

 

 

the Directory server.

privileges under the

 

 

 

default_princ_subtr

 

 

 

ee and

 

 

 

base_dn_for_search.

 

 

 

When you add a

 

 

 

Kerberos principal

 

 

 

ensure that you specify

 

 

 

it under the

 

 

 

base_dn_for_search.

 

 

 

 

 

Incorrect LDAP DN

The DN specified is

Ensure that you add

 

 

not valid.

the DN under the

 

 

 

base_dn_for_search

 

 

 

in the Directory server.

 

 

 

 

 

Unavailable or

 

Verify that the

 

invalid libldap.so

 

LDAP-UX product is

 

 

 

installed correctly on

 

 

 

the Kerberos server.

 

 

 

 

302

Chapter 11