[OpenAFS] forwarding credentials with OpenSSH, Kerberos and pam-afs-session

Ken Aaker kaaker@brocade.com
Thu, 06 Sep 2007 14:33:40 -0500


Jeffrey Altman wrote:
> Each host should only have its own keys.
>
> The client principal is selected by the user not by the host.
> The client principal comes from the user's credential cache.
>
>   
Ok, I sorted that out, but it didn't make any difference in the
behavior. "mars" will still do gssapi-with-mic, and "ralph" won't. I
tried one other thing, and set up my other 64bit machine ("sif"), that
works properly. Ah, well, if I have a working and a not-working setup I
can look for differences between them.

Thank you all gentlemen.

Ken Aaker