[OpenAFS] pam worries debian etch and KDE 3.5.x

Lars Schimmer l.schimmer@cgv.tugraz.at
Thu, 09 Nov 2006 14:12:43 +0100


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi!

I tried to setup pam access to obtain tokens/ticket automatic on my freh
installed etch-testbox.
OpenAFS 1.4.2, krb5 and libpam-krb5 and libpam-openafs-session.

Pam config:
common-account:
account         sufficient      pam_krb5.so

common-auth:
auth       sufficient   pam_krb5.so
auth       required     pam_unix.so use_first_pass

common-session:
session optional        pam_krb5.so
session optional        pam_openafs_session.so

kdm:
auth       required     pam_nologin.so
auth       required     pam_env.so readenv=3D1
auth       required     pam_env.so readenv=3D1 envfile=3D/etc/default/loc=
ale
@include common-auth
session    required     pam_limits.so
@include common-account
@include common-password
@include common-session

With debian sarge and kdm and kde 3.3.x I got a ticket while logging in
via ssh and via kdm to kde.

Now with above config I get a token via ssh login, but not via kdm login.

I=B4m not a crack with pam.d, has anyone a working config, even with
ticket-forwarding?

I=B4ve found some parts on google, but they all didn=B4t worked well enou=
gh :-(


MfG,
Lars Schimmer
- --
- -------------------------------------------------------------
TU Graz, Institut f=FCr ComputerGraphik & WissensVisualisierung
Tel: +43 316 873-5405       E-Mail: l.schimmer@cgv.tugraz.at
Fax: +43 316 873-5402       PGP-Key-ID: 0x4A9B1723
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFFUylKmWhuE0qbFyMRAiUCAJ99PlV91a1+F93m+tIBTFiOPGfG8gCfbZIm
7ADfLGetaTYELAfet5ZtDew=3D
=3DmLAh
-----END PGP SIGNATURE-----