[19734] in Kerberos

home help back first fref pref prev next nref lref last post

Re: which krb5 PAM module on Solaris 8?

daemon@ATHENA.MIT.EDU (Sam Hartman)
Fri Aug 1 15:19:43 2003

To: Tim Mooney <mooney@dogbert.cc.ndsu.NoDak.edu>, kerberos@mit.edu
From: Sam Hartman <hartmans@MIT.EDU>
Date: Fri, 01 Aug 2003 15:10:47 -0400
In-Reply-To: <3F2AA269.4000105@rit.bme.hu> (
 =?iso-8859-1?q?G=C1L_Bal=E1zs's_message_of?= "Fri, 01 Aug 2003 19:24:57
 +0200")
Message-ID: <tslbrv9gpmw.fsf@konishi-polis.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Errors-To: kerberos-bounces@mit.edu

>>>>> "GÁL" == GÁL Balázs <balsa@rit.bme.hu> writes:

    GÁL> Tim Mooney írta:
    >> All- I'm looking for recommendations on which krb5 PAM module I
    >> should use on a sparc box I'll be reinstalling with Solaris 2.8
    >> in a couple weeks.

    GÁL> pam-krb5.sf.net. This is an enhanced version of RedHat's
    GÁL> pam_krb5.  I will release rc8 in this weekend, it will
    GÁL> contains many workarounds for the solaris pam
    GÁL> implementation, so I recommend it.

Hi.  I have not looked at this specific implementation, but I have
encountered the Redhat PAM module and would like to gvie astrong
disrecommendation to that code base.

It seems like the module does way too much and has too much internal
information about the Kerberos implementation.  In particular, it even
parses krb5.conf (incorrectly).

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post