[OpenAFS] no tokens at login time via ssh

Daniel Clark dclark@pobox.com
Tue, 17 Oct 2006 14:45:26 -0400


------=_Part_73761_14331128.1161110726971
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

On 10/17/06, Kevin Scott Sumner <ksumner@physics.unc.edu> wrote:

> With just some configuration changes, the kdc authentication,
> token-getting
> and ticket-getting all worked out of the box once-upon a time... although,
> we now have compiled our own version of ssh/sshd.


This seems sort of unavoidable if you want to use some of the more advanced
OpenAFS/Kerberos related features, esp. if you must support platforms other
than Debian/Ubuntu.

Do you happen to have specs of your OpenSSH compiles anywhere?

I am also doing this; my work is up at [1]; I just got stuff to compile
cleanly, but still need to test against Kerberos 5 / PAM / OpenAFS etc.

[1] http://www.dclark.us/encaps/profiles/openssh-4.4p1.ep

Cheers,
-Danny

------=_Part_73761_14331128.1161110726971
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

<span class="gmail_quote">On 10/17/06, <b class="gmail_sendername">Kevin Scott Sumner</b> &lt;<a href="mailto:ksumner@physics.unc.edu">ksumner@physics.unc.edu</a>&gt; wrote:</span><br><div><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
With just some configuration changes, the kdc authentication, token-getting<br>and ticket-getting all worked out of the box once-upon a time... although,<br>we now have compiled our own version of ssh/sshd.</blockquote><div>
<br>This seems sort of unavoidable if you want to use some of the more advanced OpenAFS/Kerberos related features, esp. if you must support platforms other than Debian/Ubuntu.<br><br>Do you happen to have specs of your OpenSSH compiles anywhere?
<br><br>I am also doing this; my work is up at [1]; I just got stuff to compile cleanly, but still need to test against Kerberos 5 / PAM / OpenAFS etc.<br><br>[1] <a href="http://www.dclark.us/encaps/profiles/openssh-4.4p1.ep">
http://www.dclark.us/encaps/profiles/openssh-4.4p1.ep</a><br></div><br></div>Cheers,<br>-Danny<br>

------=_Part_73761_14331128.1161110726971--