[OpenAFS-devel] OpenAFS and OpenSSH, PAM, tokens

Dean Anderson dean@av8.com
Mon, 30 Oct 2006 01:56:16 -0500 (EST)


I'm just running a new 1.4.2 install on a fedora core 4 box, and the PAM
module doesn't work, again.  I think this worked some time back, on fc4,
but that might also have been with the pre-built rpms. This 1.4.2 was
made from the src.rpm with "rpbuild -bb openafs.spec".

I see that openssh is _still_ doing a pam_open_session before
pam_setcred, but having changed that in openssh (4.0p1), it still
doesn't work.  Pam module gets called--I can see the syslog'd debug
messages when I add "debug", but I get no credentials on login. 

A manual klog works, and unlog works.  Putting "use_klog" on the pam_afs
module has no effect.  What gives?

I count 96 messages on the subject of openssh on openafs-devel, and
several "FAQ"s on the problem. None solved the problem.  Can we please
update the FAQ the answer to this problem?

Thanks,

		--Dean

-- 
Av8 Internet   Prepared to pay a premium for better service?
www.av8.net         faster, more reliable, better service
617 344 9000