[OpenAFS-devel] modifying pam_afs.krb.so.1

Charles Clancy security@xauth.net
Fri, 1 Nov 2002 12:13:01 -0600 (CST)


> Your right though, I should make a seperate pam_securid.so.  I forgot
> that pam_afs.krb.so.1 is used to get a token when authenticating with
> kerberos.

Kerberos IV, that is.  The only end-user difference between pam_afs.krb
and pam_afs is that the .krb version gives you a K4 TGT in addition to an
AFS token when its done.  It makes no use of existing TGTs.

I don't think you'll be able to easily use SecureID to get an AFS token,
unless you have some intermediate Kerberos step.

[ t charles clancy ]--[ tclancy@uiuc.edu ]--[ www.uiuc.edu/~tclancy ]