[OpenAFS] [aklog] pam integration

Charles Clancy security@xauth.net
Mon, 14 Apr 2003 17:54:15 -0500 (CDT)


On Fri, 11 Apr 2003 Sebastian.Roth@frm2.tum.de wrote:

> auth            required        pam_nologin.so
> auth            required        pam_env.so
> auth            sufficient      pam_krb5.so forwardable
> auth            required        pam_unix.so try_first_pass shadow

I suggest you use pam_krb5afs instead of pam_krb5.  Then you don't need to
use pam-openafs-krb5.

> Current behavior is that user can log in, but don't have any rights to
> their home directory. (ACL's are set up properly,btw). If they type in
> `aklog` manually, access to their homes works.

Sounds like your pam-openafs-krb5 module isn't working.  Where did this
module come from?  I've not heard of it before.  Try this module instead:

	http://sourceforge.net/projects/pam-krb5/

[ t charles clancy ]--[ tclancy@uiuc.edu ]--[ www.uiuc.edu/~tclancy ]