Red Hat DIRECTORY SERVER 8.0 Command Reference Manual page 185

Hide thumbs Also See for DIRECTORY SERVER 8.0:
Table of Contents

Advertisement

Table 6.8, "Description of GSSAPI SASL Mechanism Options"
• GSSAPI, described in
Required or Optional
Required
Required
Optional
Option
mech=CRAM-MD5
authid=authid_value
secprop=value
Description
Gives the SASL
mechanism.
Gives the ID used to
authenticate to the
server. authid_value
can be the following:
• UID. For example,
msmith.
• u: uid. For example,
u: msmith.
• dn: dn_value. For
example, dn:
uid=msmith,ou=People,o=example.com.
The secprop attribute
sets the security
properties for the
connection. The
secprop value can be
any of the following:
• None
• noplain — Do not
permit mechanisms
susceptible to simple
passive attack.
• noactive — Do not
permit mechanisms
susceptible to active
attacks.
• nodict — Do not
permit mechanisms
susceptible to
passive dictionary
attacks.
• forwardsec —
Require forward
secrecy.
• passcred — Attempt
to pass client
credentials.
• noanonymous
— Do not permit
ldapsearch
Example
-o "mech=CRAM-MD5"
-o
"authid=dn:uid=msmith,ou=People,o=
-o
"secprop=noplain,minssf=1,maxbufsi
175

Advertisement

Table of Contents
loading

Table of Contents