[2126] in Kerberos

home help back first fref pref prev next nref lref last post

Re: kerberized login under aix

daemon@ATHENA.MIT.EDU (Lucien W. Van Elsen)
Tue Aug 25 13:58:25 1992

Date: 25 Aug 92 17:27:26 GMT
From: lwvanels@Athena.MIT.EDU (Lucien W. Van Elsen)
Reply-To: lwvanels@mit.edu
To: kerberos@shelby.Stanford.EDU

pulverg@CPSEC.CPMC.COLUMBIA.EDU (Gerald E Pulver) writes:
>   Has anyone out there had experience kerberizing login on an aix machine?
>   If so: did you just use login.krb as a direct drop-in replacement for 
>   /bin/login or did you establish kerberos as an alternate authentication
>   method in login.cfg, to be referred to on a case-by-case basis in the
>   Primary Authenication field of SMIT?

I managed to get login.krb somewhat working under AIX with a moderate amount
work; the security routines and methods for starting up a new session are
fairly different.  The "somewhat working" is due to the fact that while the
login would work for network access (replacing /bin/login), I could not
manage to get it to work on the console, apparently due to some HFT magic
that I was missing.  Since we also desired to add some features to the login
program, establishing an alternate authentication method wasn't sufficient.
We eventually ended up using a modified version Transarc's (proprietary)
login.

However, if you don't need to add any additional features, adding an
alternate authentication method is what I'd recommend; the interface is
fairly flexible, though somewhat poorly documented.

	-Lucien

----------------------------------------------------------------------------
Lucien Van Elsen               | lwvanels@mit.edu
			       | The secret to a long life is knowing when
			       | it's time to go..

home help back first fref pref prev next nref lref last post