No write access to parent open ldap kerberos

Help pls : KDC w/LDAP backend

We are debating on the use of kerberos in big data cluster that we have. Our admin wants to use ldap for authentication and authorization.

I looked up into the internet and got mixed response but there was no clear understanding for the reason to use kerberos. The LDAP server runs on FreeBSD and was set up with the following: Heimdal OpenLDAP Cyrus SASL The problem is that the write access, e.g.

adding a new entry, is only successful when I bind to the server as rootdn, i.e. "cn=ldapadmin,cn=gssapi,cn=auth".

