Subject: Re: PAM and OpenSSH
To: Emmanuel Dreyfus <manu@netbsd.org>
From: Roland Dowdeswell <elric@imrryr.org>
List: tech-userlevel
Date: 01/25/2005 16:07:19
On 1106686744 seconds since the Beginning of the UNIX epoch
Emmanuel Dreyfus wrote:
>

>As far as I understand, we use the non portable OpenSSH from OpenBSD,
>and it does not support PAM. In order to bring PAM support into sshd we
>need to switch to portable OpenSSH.
>
>How intrusive is that change? Is there any special care to have in this
>operation?
>
>In this document
>http://www.netbsd.org/Documentation/software/3rdparty/
>we talk about kerberos IV support, doesn't this problem just disapear if
>we use PAM?

We also need to resurrect the protocol 1 krb5 and protocol 2 krb5
support which OpenSSH removed.  I've been planning to do this when
I get a chance, but the chance has been taking a while to show up.

--
    Roland Dowdeswell                      http://www.Imrryr.ORG/~elric/