>binddn="cn=HOSTNAME,cn=ldap,cn=operational,dc=stanford,dc=edu" > authcId=ldap/HOSTNAME.stanford.edu@stanford.edu SASL should let you omit the binddn/authcid and have it determined from the ticket. Not sure how you configure this with OpenLDAP though. -- Luke --