| home | help | back | first | fref | pref | prev | next | nref | lref | last | post |
Message-ID: <49B80608.6060607@mit.edu> Date: Wed, 11 Mar 2009 14:42:16 -0400 From: Evan Broder <broder@MIT.EDU> MIME-Version: 1.0 To: Tim Abbott <tabbott@mit.edu> CC: Greg Price <price@mit.edu>, Geoffrey Thomas <geoffrey@mit.edu>, debathena@mit.edu In-Reply-To: <alpine.DEB.1.10.0903102320480.17034@vinegar-pot.mit.edu> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Tim Abbott wrote: > On Tue, 10 Mar 2009, Greg Price wrote: > > >> To summarize this possibly more clearly for people without full >> context, Intrepid introduced a new order of things for PAM >> configuration, with the name pam-auth-update; I adapted our PAM config >> to this form, which includes supplying static config files in >> /usr/share/pam-configs/ that can be turned on or off by the sysadmin; >> then it looks like in Jaunty, libpam-krb5 upstream supplies a krb5 >> config file with the obvious name, the same one I used. >> >> >> Evan and I looked at this last night. Among other things, the >> /usr/share/pam-configs/krb5 in the new libpam-krb5 only acts for >> uid >= 1000. It'd be nice if that worked for us, but right now it >> doesn't. >> >> Unfortunately pam-auth-update reads every file in >> /usr/share/pam-configs/ other than . and .., so diverting will be a >> pain. I can probably get the maintainer to take a patch to use >> run-parts semantics, which is the Debian Way for this sort of thing. >> Not sure that would happen for jaunty. >> > > Can't we use DEB_REMOVE_FILES to disable their configuration for now? > > -Tim Abbot Yeah - DEB_REMOVE_FILES would be the right hammer for this. We may want to use that as an opportunity to rename it to debathena-libpam-krb5-config, because, now that upstream has a patch of their own, I think this package becomes pretty clearly rooted as a Debathenaism. - Evan
| home | help | back | first | fref | pref | prev | next | nref | lref | last | post |