[OpenAFS] Last very few steps: hints please!

Sergio Gelato Sergio.Gelato@astro.su.se
Thu, 1 Apr 2004 16:07:54 +0200

* Sensei [2004-04-01 15:30:43 +0200]:
> Sergio Gelato wrote:
> >>which works fine for me. though that's just a pam module for setting
> >>up a pag, and getting tokens. you'll still need the openafs kernel
> >>modules and client.
> >
> >Amazing. I've never been able to make woody's libpam-openafs-session
> >work properly, always considered it terminally broken.

[Did my entire message, which contained far more than the above statement,
go to the whole list? I think I un-cc:ed the list on this occasion, to save
the moderator some work (I'm subscribed under a different, confidential
address, so my posts get the non-subscriber treatment). Also, I'd rather
keep this for debian-kerberos, where it has however already been discussed
at length in the past. The main focus is now on Debian sarge anyway.]

> It works fine for me :) with this pam modifications:
> /etc/pam.d/login

Ah yes, but I'm more interested in gdm (and used to be also interested in
ssh, which is an even bigger can of worms where PAM is concerned). 
> fs mkmount /afs/.cell.name
> really necessary? We don't have a replication server...

You don't have one *yet*. But having /afs/.cell.name doesn't hurt, and
adherence to de facto standards is usually a good idea.

Note that with -dynroot you get the /afs/.cell.name entries automatically.