[OpenAFS] Problem with pam on debian with 1.3.81 kernel 2.6.11

Derek Atkins warlord@MIT.EDU
Thu, 14 Apr 2005 14:20:49 -0400


Jim Rees <rees@umich.edu> writes:

>   Personally I can't get -K to work, but it might be due to my PAM
>   configuration.
>
> I couldn't get GSSAPIDelegateCredentials to work until I also set
> GSSAPIAuthentication.  I think you also need forwardable=true in krb5.conf.
> But the biggest problem for me is it only works for a single realm.
>
> I wish we still had afs token forwarding in ssh.

I can't seem to get the verion in FC3 to work at all.  It's 3.9p1,
and it seems to support gssapi-with-mic but apparantly the servers
I'm trying to contact only support "gssapi".  :(

debug1: Authentications that can continue: external-keyx,gssapi,password
debug3: start over, passed a different list external-keyx,gssapi,password
debug3: preferred gssapi-with-mic,publickey,keyboard-interactive,password
debug3: authmethod_lookup password
debug3: remaining preferred: ,publickey,keyboard-interactive,password
debug3: authmethod_is_enabled password
debug1: Next authentication method: password

-derek
-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       warlord@MIT.EDU                        PGP key available