When you use DIGEST-MD5 binding and specify the DNS name of the directory server in an ldapsearch command, the system that runs the ldapsearch command must resolve the DNS name of the directory in the same way the directory server resolves the name, for example:
If directory server dirsvr1 resolves to dirsvr1.teradata.com on the directory server system, the dirsvr1 must also resolve to dirsvr1.teradata.com on the system where the ldapsearch runs. If the Teradata Vantage server does not resolve it in the same way, the directory authentication fails.
The DIGEST-MD5 authentication protocol used by LDAP is deprecated. Teradata strongly recommends you use simple binding with TLS protection, and stop using DIGEST-MD5.