configuring libkadm5clnt_mit/libkadm5 for NIS password migration in Fedora

Robert Kudyba rkudyba at fordham.edu
Mon Nov 9 16:45:35 EST 2020


I posted a few weeks back about migrating our NIS user passwords and
the response
I got was
<https://mailman.mit.edu/pipermail/kerberos/2020-October/022559.html>:
"In Fedora, libkadm5clnt_mit.so is provided by libkadm5. Please be aware
that neither I (Fedora maintainer) do not support external programs using
the libkadm5 interface."

I'm trying to determine how to configure PAM to get this password migration
library to work. I posted on Reddit
<https://www.reddit.com/r/sysadmin/comments/jmxf6w/migrating_nis_password_to_kerberos_on_fedorared/>,
to no avail.

What needs to go in /etc/authselect/password-auth and/or
/etc/authselect/system-auth? I tried putting:
auth optional pam_krb5_migrate.so.1 expire_pw

But I get this error:

debug1: PAM: initializing for "myuser" PAM unable to resolve symbol:
pam_sm_authenticate PAM unable to resolve symbol: pam_sm_setcred

Any guidance would be greatly appreciated.

Thanks.

Rob


More information about the Kerberos mailing list