Re: KEYRING:persistent and ssh

Charles Hedrick <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <[email protected]>
yes. https://github.com/clhedrick/kerberos  pam_reg_cc.

However this module does additional things, primarily registering cc’s for renewd to renew. If you’re not using renewd, you might want to remove the call to register_for_delete


> On Apr 13, 2020, at 1:13:21 AM, Ken Dreyer <[email protected]> wrote:
> 
> On Tue, Apr 7, 2020 at 8:39 AM Charles Hedrick <[email protected]> wrote:
>> 
>> we use a pam module that normalizes the credential cache. If krb5.conf
>> asks for KEYRING and sshd leaves the cache in /tmp, the code moves it
>> into KEYRING and updates KRB5CCNAME.
> 
> Is this pam module open-source? It sounds like you've implemented what
> Russ described earlier in this thread.
> 
>> However there’s a gotcha. Kerberized NFS uses (by default) the
>> currently selected principal. So for a collection to be useful, we
>> also have a ccselect plugin to make sure that NFS (actually rpc.gssd)
>> always gets the right principal from the collection.
> 
> I'm interested in this as well, if it's open-source!
> 
> - Ken


________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.