[2126] in Kerberos
Re: kerberized login under aix
daemon@ATHENA.MIT.EDU (Lucien W. Van Elsen)
Tue Aug 25 13:58:25 1992
Date: 25 Aug 92 17:27:26 GMT
From: lwvanels@Athena.MIT.EDU (Lucien W. Van Elsen)
Reply-To: lwvanels@mit.edu
To: kerberos@shelby.Stanford.EDU
pulverg@CPSEC.CPMC.COLUMBIA.EDU (Gerald E Pulver) writes:
> Has anyone out there had experience kerberizing login on an aix machine?
> If so: did you just use login.krb as a direct drop-in replacement for
> /bin/login or did you establish kerberos as an alternate authentication
> method in login.cfg, to be referred to on a case-by-case basis in the
> Primary Authenication field of SMIT?
I managed to get login.krb somewhat working under AIX with a moderate amount
work; the security routines and methods for starting up a new session are
fairly different. The "somewhat working" is due to the fact that while the
login would work for network access (replacing /bin/login), I could not
manage to get it to work on the console, apparently due to some HFT magic
that I was missing. Since we also desired to add some features to the login
program, establishing an alternate authentication method wasn't sufficient.
We eventually ended up using a modified version Transarc's (proprietary)
login.
However, if you don't need to add any additional features, adding an
alternate authentication method is what I'd recommend; the interface is
fairly flexible, though somewhat poorly documented.
-Lucien
----------------------------------------------------------------------------
Lucien Van Elsen | lwvanels@mit.edu
| The secret to a long life is knowing when
| it's time to go..