#kerberos user dn: uid=kdc,cn=sysaccounts,cn=etc,$SUFFIX changetype: add objectclass: account objectclass: simplesecurityobject uid: kdc userPassword: $PASSWORD #kerberos base object dn: cn=kerberos,$SUFFIX changetype: add objectClass: krbContainer objectClass: top cn: kerberos aci: (targetattr="*")(version 3.0; acl "KDC System Account"; allow (all) userdn= "ldap:///uid=kdc,cn=sysaccounts,cn=etc,$SUFFIX";) #sasl mapping dn: cn=fullprinc,cn=mapping,cn=sasl,cn=config changetype: add objectclass: top objectclass: nsSaslMapping cn: fullprinc nsSaslMapRegexString: \(.*\)@\(.*\) nsSaslMapBaseDNTemplate: $SUFFIX nsSaslMapFilterTemplate: (krbPrincipalName=\1@\2) dn: cn=justname,cn=mapping,cn=sasl,cn=config changetype: add objectclass: top objectclass: nsSaslMapping cn: justname nsSaslMapRegexString: \(.*\) nsSaslMapBaseDNTemplate: $SUFFIX nsSaslMapFilterTemplate: (krbPrincipalName=\1@$REALM)