Hallo,
das erste geht einwandfrei:
root@ucs:~# kinit Administrator
Administrator@KNEBB.DE's Password:
root@ucs:~# klist
Credentials cache: FILE:/tmp/krb5cc_0
Principal: Administrator@KNEBB.DE
Issued Expires Principal
Feb 10 16:11:45 2016 Feb 11 02:11:42 2016 krbtgt/KNEBB.DE@KNEBB.DE
root@ucs:~#
Rejcts des S4-Connectors finde ich KEINE:root@ucs:/var/log/univention# grep -i reject connector-s4.log
Aber es besteht wohl ein Problem mit dem sync:
[code]
root@ucs:/var/log/univention# univention-ldapsearch -b “uid=administrator,cn=users,dc=knebb,dc=de”
extended LDIF
LDAPv3
base <uid=administrator,cn=users,dc=knebb,dc=de> with scope subtree
filter: (objectclass=*)
requesting: ALL
Administrator, users, knebb.de
dn: uid=Administrator,cn=users,dc=knebb,dc=de
uid: Administrator
krb5PrincipalName: Administrator@KNEBB.DE
uidNumber: 2002
sambaAcctFlags: [U ]
krb5MaxLife: 86400
cn: Administrator
[…][/code]
s4 zeigt aber Probleme und läßt sich nicht syncen:
root@ucs:/var/log/univention# univention-s4search -b "uid=administrator,cn=users,dc=knebb,dc=de"
Failed to bind - LDAP error 49 LDAP_INVALID_CREDENTIALS - <SASL:[GSS-SPNEGO]: NT_STATUS_LOGON_FAILURE> <>
Failed to connect to 'ldaps://ucs.knebb.de' with backend 'ldaps': (null)
Failed to connect to ldaps://ucs.knebb.de - (null)
root@ucs:/var/log/univention# /usr/share/univention-s4-connector/resync_object_from_ucs.py --filter uid=Administrator
resync triggered for uid=Administrator,cn=users,dc=knebb,dc=de
root@ucs:/var/log/univention# univention-s4search -b "uid=administrator,cn=users,dc=knebb,dc=de"
Failed to bind - LDAP error 49 LDAP_INVALID_CREDENTIALS - <SASL:[GSS-SPNEGO]: NT_STATUS_LOGON_FAILURE> <>
Failed to connect to 'ldaps://ucs.knebb.de' with backend 'ldaps': (null)
Failed to connect to ldaps://ucs.knebb.de - (null)
Sorry, mit ldapsearch kenne ich mich zu wenig aus, nach was sollte ich da suchen?
Grüeß
Christian Völker