binddn="cn=HOSTNAME,cn=ldap,cn=operational,dc=stanford,dc=edu" authcId=ldap/HOSTNAME.stanford.edu@stanford.edu
SASL should let you omit the binddn/authcid and have it determined from the ticket. Not sure how you configure this with OpenLDAP though.
--Quanah
-- Quanah Gibson-Mount Principal Software Developer ITSS/Shared Services Stanford University GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html
"These censorship operations against schools and libraries are stronger than ever in the present religio-political climate. They often focus on fantasy and sf books, which foster that deadly enemy to bigotry and blind faith, the imagination." -- Ursula K. Le Guin