[22566] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Solaris pam_krb5 session cleanup

daemon@ATHENA.MIT.EDU (dkuhl)
Fri Sep 24 12:20:49 2004

Message-ID: <41542920.7010908@paritysys.net>
Date: Fri, 24 Sep 2004 09:03:12 -0500
From: dkuhl <dkuhl@paritysys.net>
MIME-Version: 1.0
To: "Henry B. Hotz" <hotz@jpl.nasa.gov>
In-Reply-To: <2C2728B6-0DCE-11D9-8E75-000A95CA746C@jpl.nasa.gov>
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit
cc: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

	Not sure about S9 in particular, but in Linux you normally modify the 
/etc/login.defs file.  The value is "CLOSE_SESSIONS".

   Here's the relevent part of the file:
#
# Enable pam_close_session() calling. When using normal (pam_unix.so)
# session handling modules, this is not needed. However with modules
# (such as kerberos or other persistent session models), login and su
# need to fork and wait for the shell to exit so that sessions can be
# cleaned up.
#
CLOSE_SESSIONS yes

	Of course, for all I know S9 doesn't have this file, but it should have 
something analogous.

D.

David Kuhl
Parity Systems
dkuhl@paritysys.com
-----------------------



Henry B. Hotz wrote:
> The pam_krb5 session module is supposed to clean up your credentials on  
> logout (if you are the last logout for that session).
> 
> I had a Solaris 9 machine which did that.  Now I have a different S9  
> machine which doesn't.  Any suggestions for what to look for?
> ------------------------------------------------------------------------ 
> ----
> The opinions expressed in this message are mine,
> not those of Caltech, JPL, NASA, or the US Government.
> Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu
> 
> ________________________________________________
> Kerberos mailing list           Kerberos@mit.edu
> https://mailman.mit.edu/mailman/listinfo/kerberos
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post