home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.kerberos
- Path: sparky!uunet!gatech!bloom-beacon!bloom-picayune.mit.edu!athena.mit.edu!lwvanels
- From: lwvanels@athena.mit.edu (Lucien W. Van Elsen)
- Subject: Re: kerberized login under aix
- In-Reply-To: pulverg@CPSEC.CPMC.COLUMBIA.EDU's message of Thu, 20 Aug 1992 18:09:36 GMT
- Message-ID: <LWVANELS.92Aug25132717@fionavar.mit.edu>
- Sender: news@athena.mit.edu (News system)
- Nntp-Posting-Host: fionavar.mit.edu
- Reply-To: lwvanels@MIT.EDU
- Organization: Massachusetts Institute of Technology
- References: <CMM.0.90.0.714334176.pulverg@cpsec.cpmc.columbia.edu>
- Date: Tue, 25 Aug 1992 17:27:26 GMT
- Lines: 27
-
- pulverg@CPSEC.CPMC.COLUMBIA.EDU (Gerald E Pulver) writes:
- > Has anyone out there had experience kerberizing login on an aix machine?
- > If so: did you just use login.krb as a direct drop-in replacement for
- > /bin/login or did you establish kerberos as an alternate authentication
- > method in login.cfg, to be referred to on a case-by-case basis in the
- > Primary Authenication field of SMIT?
-
- I managed to get login.krb somewhat working under AIX with a moderate amount
- work; the security routines and methods for starting up a new session are
- fairly different. The "somewhat working" is due to the fact that while the
- login would work for network access (replacing /bin/login), I could not
- manage to get it to work on the console, apparently due to some HFT magic
- that I was missing. Since we also desired to add some features to the login
- program, establishing an alternate authentication method wasn't sufficient.
- We eventually ended up using a modified version Transarc's (proprietary)
- login.
-
- However, if you don't need to add any additional features, adding an
- alternate authentication method is what I'd recommend; the interface is
- fairly flexible, though somewhat poorly documented.
-
- -Lucien
-
- ----------------------------------------------------------------------------
- Lucien Van Elsen | lwvanels@mit.edu
- | The secret to a long life is knowing when
- | it's time to go..
-