Using Kerberos

To bind using a Kerberos identity, specify connect type GSSAPI on the eimadmin command. No other credential information is required, but the default Kerberos credential must have been established through a service such as kinit prior to entering the command.
kinit eimadministrator@realm.com  

eimadmin 
-lD 
-d 'ibm-eimDomainName=MyDomain,o=ibm,c=us' 
-h ldap://some.ldap.host 
-S GSSAPI
For access checking, LDAP considers a distinguished name formed by prefixing the Kerberos principal name with "ibm-kgn=" or distinguished names located through special mapping or searches. See z/OS IBM Tivoli Directory Server Administration and Use for z/OS for more information.