[OpenAFS] SSH: pag after ticket forwarding

Franco "Sensei" Sensei <senseiwa@tin.it>
Fri, 25 Feb 2005 10:55:54 -0600


This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig36E237D5739362CB7489BAA1
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit

John Koyle wrote:
> Make sure you are using the pam module.  Here's the 
> /etc/security/pam_unix2.conf file on all my suse systems:
> 
> auth:   call_modules=krb5afs nullok
> account:        use_ldap call_modules=krb5afs
> password:       call_modules=krb5afs nullok
> session:        none

This is my pam_unix2.conf:

auth:           call_modules=krb5afs
account:        call_modules=krb5afs
password:       call_modules=krb5afs
session:        call_modules=krb5afs


I don't use use_ldap in pam_unix2 since I have nsswitch.conf set up for 
password, group and shadow to ``files ldap''.

> You may not have LDAP installed on your systems though, so the main 
> thing you're after is the krb5afs entries.  I am using the stock OpenSSH 
> and OpenAFS on all my SuSE boxes and everything works fine, no patches 
> needed.

Don't see the important difference between me and you... in both cases 
we use krb5afs except nullok, which should be ininfluent... I think...

-- 
Sensei <mailto:senseiwa@tin.it> <pgp:8998A2DB>
        <icqnum:241572242>
        <yahoo!:sensei_sen>
        <msn-id:sensei_sen@hotmail.com>

--------------enig36E237D5739362CB7489BAA1
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFCH1id4LBKhYmYotsRAoGwAKCCrMbLl+ZEC71AtQ+WuXPRv4CdVgCeMAnY
2qS6QD1SdDt7vFKisvko05c=
=b6Xc
-----END PGP SIGNATURE-----

--------------enig36E237D5739362CB7489BAA1--