[OpenAFS] kaserver vs. Kerberos IV

Charles Clancy security@xauth.net
Mon, 28 Oct 2002 12:02:04 -0600 (CST)


On 28 Oct 2002, Christian Pfaffel wrote:
>
> Is there a way to configure a standard xscreensaver/xlock to
> renew/replace the kerberos V ticket and obtain a newer AFS token, so
> that I will always have a valid token to access my AFS homespace.

Just use pam_krb5 for authentication; that should get you a new TGT.

Then, pam_openafs-session should be able to get you a new token.  You need
to have pam_openafs-session NOT get a new PAG for you, otherwise that new
token will die with xscreensaver.  I'm not sure if there's an option to do
that or not.  If not, it should be added.

[ t charles clancy ]--[ tclancy@uiuc.edu ]--[ www.uiuc.edu/~tclancy ]