configuring libkadm5clnt_mit/libkadm5 for NIS password migration in Fedora

Robert Kudyba <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general
Message-ID <CAFHi+KSwFe3TvodoCOED_-Uit68625Jy6Y7UZFYwv9=dpjnz6A@mail.gmail.com>
I posted a few weeks back about migrating our NIS user passwords and
the response
I got was
<https://mailman.mit.edu/pipermail/kerberos/2020-October/022559.html>:
"In Fedora, libkadm5clnt_mit.so is provided by libkadm5. Please be aware
that neither I (Fedora maintainer) do not support external programs using
the libkadm5 interface."

I'm trying to determine how to configure PAM to get this password migration
library to work. I posted on Reddit
<https://www.reddit.com/r/sysadmin/comments/jmxf6w/migrating_nis_password_to_kerberos_on_fedorared/>,
to no avail.

What needs to go in /etc/authselect/password-auth and/or
/etc/authselect/system-auth? I tried putting:
auth optional pam_krb5_migrate.so.1 expire_pw

But I get this error:

debug1: PAM: initializing for "myuser" PAM unable to resolve symbol:
pam_sm_authenticate PAM unable to resolve symbol: pam_sm_setcred

Any guidance would be greatly appreciated.

Thanks.

Rob
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.