kinit failure with Kerberos and LDAP backend

Rainer Laatsch Laatsch at
Tue Oct 30 14:57:35 EDT 2012

On Fri, 26 Oct 2012, Booker Bense wrote:

> Do yourself a big favor and put kerberos entities in ou=Accounts.
> There is not a one to one
> relationship between accounts and people and you will make your life
> much easier in the
> future if you clearly make the split now.

How and when would errors show up (if no split) ?

> If you are going to use your ldap server only for a NIS replacement,
> then you might
> get by with just one ou. But that really limits where you can go in the future.

Could you, please, explain that?

> - Booker C. Bense
> ________________________________________________
> Kerberos mailing list           Kerberos at

R. Laatsch

More information about the Kerberos mailing list