3.1.1.3.4.5.1 GSSAPI

The presence of the "GSSAPI" string value in the supportedSASLMechanisms attribute indicates that the DC accepts the GSSAPI security mechanism for LDAP bind requests. The GSSAPI mechanism for SASL is described in [RFC2222] section 7.2, and GSSAPI is described in more detail in [RFC2078]. Active Directory supports Kerberos when using GSSAPI; see [MS-KILE] and [RFC1964] for details of Kerberos.