[OpenAFS] AFS + LDAP + PAM + SSH

Sensei senseiwa@tin.it
Thu, 16 Sep 2004 11:37:09 +0200


--=-ow7oeOU5tmqfyhtbXgmn
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

On Wed, 2004-09-15 at 17:46, Maurizio Santini wrote:
> I've installed kerberos and got it work (I can get a ticket using kinit
> or login from a terminal) but the problem is the AFS token that doesn't
> get assigned.
>=20
> I've read about the afs to kerberos migration kit and I wonder if I have
> to apply it to be able to use aklog and alike or if it's enough
> modifying /etc/pam.d/login file.

Simple, just install aklog and pam_openafs_session (both are contained
in two debian packages, availabe for woody) and use

session     optional    pam_krb5.so
session     optional    pam_openafs_session.so

In your login (pam). Works fine.

--=20
Sensei <mailto:senseiwa@tin.it>
         =20
The optimist says "Tomorrow is sunday".
The pessimist says "The day after tomorrow is moday". (Gustave Flaubert)

--=-ow7oeOU5tmqfyhtbXgmn
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)

iD8DBQBBSV7F4LBKhYmYotsRAnamAJkBXJ6S2OgCTMYU45gLSxzENm46fgCePpfa
C4hYBKh95nCXpnpH2cAONrs=
=vODi
-----END PGP SIGNATURE-----

--=-ow7oeOU5tmqfyhtbXgmn--