manu <ManuX@rstack.org> writes:

> Hello,
> I have already made some successful tests with
> - PKINIT with a heimdal snapshot on one hand
> - the PAM module from Mario Strasser pkcs11_login and also the PAM
> module that comes with opensc on the other hand.
> Does anyone have already try merging those too points in order to
> achieve a 2 factors authentication with Kerberos?

I've been thinking about how to do integrate pkcs-11 with the CMS stuff
(pkinit uses CMS). I want to be able to support hardware token for both the
KDC and the clients. So far I'm not happy with the tools that exists.

Its on my todo list, slowly working toward the goal.


