[OpenAFS] SSH: pag after ticket forwarding
Franco "Sensei"
Sensei <senseiwa@tin.it>
Fri, 25 Feb 2005 10:55:54 -0600
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig36E237D5739362CB7489BAA1
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
John Koyle wrote:
> Make sure you are using the pam module. Here's the
> /etc/security/pam_unix2.conf file on all my suse systems:
>
> auth: call_modules=krb5afs nullok
> account: use_ldap call_modules=krb5afs
> password: call_modules=krb5afs nullok
> session: none
This is my pam_unix2.conf:
auth: call_modules=krb5afs
account: call_modules=krb5afs
password: call_modules=krb5afs
session: call_modules=krb5afs
I don't use use_ldap in pam_unix2 since I have nsswitch.conf set up for
password, group and shadow to ``files ldap''.
> You may not have LDAP installed on your systems though, so the main
> thing you're after is the krb5afs entries. I am using the stock OpenSSH
> and OpenAFS on all my SuSE boxes and everything works fine, no patches
> needed.
Don't see the important difference between me and you... in both cases
we use krb5afs except nullok, which should be ininfluent... I think...
--
Sensei <mailto:senseiwa@tin.it> <pgp:8998A2DB>
<icqnum:241572242>
<yahoo!:sensei_sen>
<msn-id:sensei_sen@hotmail.com>
--------------enig36E237D5739362CB7489BAA1
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFCH1id4LBKhYmYotsRAoGwAKCCrMbLl+ZEC71AtQ+WuXPRv4CdVgCeMAnY
2qS6QD1SdDt7vFKisvko05c=
=b6Xc
-----END PGP SIGNATURE-----
--------------enig36E237D5739362CB7489BAA1--