[32513] in Kerberos

home help back first fref pref prev next nref lref last post

Re: pam_krb5 questions

daemon@ATHENA.MIT.EDU (Russ Allbery)
Thu Jul 15 16:15:05 2010

From: Russ Allbery <rra@stanford.edu>
To: kerberos@mit.edu
In-Reply-To: <AANLkTikWNaywCBbPMQEOzzukXPscff0EkHSVmCL6Yu1k@mail.gmail.com>
	(Techie's message of "Thu, 15 Jul 2010 12:15:05 -0700")
Date: Thu, 15 Jul 2010 13:14:59 -0700
Message-ID: <87aapssdrw.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Techie <techchavez@gmail.com> writes:

> However, If I put this in appdefaults and add a .k5login with
> joejohnson@EXAMPLE.COM in /home/joe, I can login via ssh fine.. This is
> only with Debian!!, RHEL still fails.

> [appdefaults]
>               forwardable = true
>               pam = {
>                 minimum_uid = 100
>                  EXAMPLE.COM = {
>                       search_k5login = true
>                   }
>               }

Indeed, the lack of support for this in Red Hat's pam_krb5 is the
motivating reason why I wrote my pam-krb5 module.

-- 
Russ Allbery (rra@stanford.edu)             <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post