[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [OpenAFS-devel] New OpenSSH

On Wed, 25 Feb 2004, Douglas E. Engert wrote:
> Do you have some PAM routine yo get the AFS token? 

  No. We have to support SSH also on pamless platforms.

> Did you set "KerberosGetAFSToken yes" in the sshd_config?

  Sure. And it works correctly for K5-password, but not with 
  gssapi-with-mic. The reason why it does work in this
  way was just explained by Simon Wilkinson in his previous
  posting: it was *designed* to work in this manner.

> (I have a newer version whihc does the setpag in the current 
> process)

  Please send it to me, maybe I will manage to combine it with
  3.8p1. I first thought I could easily do the same trick as
  we did in 3.7.1p2, but I was wrong. Whatever happens, I don't
  want to renounce the passwordless and tokenized gssapi cruising
  among machines. It is just what we all want.

  Thanks and greetings - Andrei.