Help: Can OpenSSH get OpenAFS token after the client login?
Simon Wilkinson
simon at sxw.org.uk
Sat Jun 11 13:56:56 EDT 2011
On 11 Jun 2011, at 18:22, "Markus Moeller" <huaraz at moeller.plus.com> wrote:
> If I remember right when GSSAPIauthentication is used and the client has a
> valid Kerberos ticket pam won't be called on the server, so the pam module
> won't help in that case.
No, the PAM stack is invoked whatever mechanism has been used to authenticated the user. Russ's pam_afs_session works perfectly to add AFS tokens for users authenticated with Kerberos tickets.
S.
>
More information about the Kerberos
mailing list