[OpenAFS] aklog PAM module

Charles Clancy mgrtcc@cs.rose-hulman.edu
Wed, 30 May 2001 22:49:39 -0500 (EST)


In a Kerberized AFS environment, you can use a Kerberos PAM module (such
as the one that comes with Solaris 8) to allow logins, but there
apparently hasn't been anything that will run aklog to get an AFS token
for you automatically.  You can put aklog in your system login script, or
you can use some of the patched daemons that come the migration kit, but
that won't work if you're trying to support ProFTPd or UW-IMAP.

So, I wrote a simple little PAM module that when used in conjunction with
Kerberos PAM will get a TGT and AFS token for users logging in, regardless
of what service they using.

It's downloadable via:
ftp://ftp.cs.rose-hulman.edu/pub/misc/pam-aklog/pam-aklog-1.0.tar.gz

I've tested it with RedHat 7.1 and Solaris 8 (sparc).
_______________________________________________________
      Charles Clancy -- mgrtcc@cs.rose-hulman.edu
Senior UNIX Administrator, Rose-Hulman Computer Science