[OpenAFS] optaining a token after openssh GSSAPI credential-delegation

Alexander Bergolth leo@strike.wu-wien.ac.at
Tue, 13 Sep 2005 22:09:39 +0200

On 12.09.2005 21:17, Douglas E. Engert wrote:
> See https://lists.openafs.org/pipermail/openafs-info/2005-May/017905.html
> This shows how to use PAM with ssh. It also works on Solaris 10.

Thanks for the hint!

FYI: For all Fedora and Redhat users:
The CVS version of the pam_krb5 RPM shipped with Fedora has support for 
credential delegation: The new "external" option.

I've just added
session     optional      /lib/security/$ISA/pam_krb5.so external
... to /etc/pam.d/system-auth


P.S.: You can get the new pam_krb5 version with:
cvs -d :pserver:anoncvs@rhlinux.redhat.com:/usr/local/CVS login
cvs -d :pserver:anoncvs@rhlinux.redhat.com:/usr/local/CVS co \
   -r HEAD pam_krb5

Alexander.Bergolth@wu-wien.ac.at                Fax: +43-1-31336-906050
Zentrum fuer Informatikdienste - Wirtschaftsuniversitaet Wien - Austria