]> git.michaelhowe.org Git - packages/o/openafs.git/commitdiff
* Suggest the same PAM settings for pam_krb5 that libpam-krb5 does.
authorRuss Allbery <rra@debian.org>
Mon, 5 Dec 2005 23:15:29 +0000 (23:15 +0000)
committerRuss Allbery <rra@debian.org>
Mon, 5 Dec 2005 23:15:29 +0000 (23:15 +0000)
debian/README.Debian
debian/changelog

index 6893a8dcb7ea096871a1aa5a39f042fd6313940b..9551ed1c2d0e55a867aa451a1767448ee1760cf8 100644 (file)
@@ -71,19 +71,19 @@ PAM Authentication
   and libpam-openafs-session packages and then put something like the
   following in /etc/pam.d/common-auth:
 
-      auth    [success=ok default=1]  pam_krb5.so
+      auth    [success=ok default=1]  pam_krb5.so ignore_root
       auth    [default=done]          pam_openafs_session.so
       auth    required                pam_unix.so nullok_secure try_first_pass
 
   and something like the following in /etc/pam.d/common-session:
 
-      session optional        pam_krb5.so
+      session optional        pam_krb5.so ignore_root
       session optional        pam_openafs_session.so
       session required        pam_unix.so
 
   You'll probably also want the following in /etc/pam.d/common-account:
 
-      account sufficient      pam_krb5.so
+      account required        pam_krb5.so ignore_root
       account required        pam_unix.so
 
   There are, of course, many variations depending on what different
@@ -112,4 +112,4 @@ PAM Authentication
   the openafs-kpasswd package to get the administrative utilities for
   managing those Kerberos accounts.
 
- -- Russ Allbery <rra@stanford.edu>, Fri Sep  9 14:53:22 2005
+ -- Russ Allbery <rra@debian.org>, Mon Dec  5 15:15:09 2005
index e996197a3a859035e22804f7d11fd2a591a35769..bb8929d644eadab7b968de60f2621aa548965da0 100644 (file)
@@ -1,5 +1,6 @@
 openafs (1.4.0-2) unstable; urgency=low
 
+  * Suggest the same PAM settings for pam_krb5 that libpam-krb5 does.
   * Update uploader address.
 
  --