|
2010-12-01 16:22 AEST by Arthur Barrett - This can be fixed by changing /etc/pam.d/cvsnt from:
# login: auth account password session
auth required pam_nologin.so
auth sufficient pam_securityserver.so
auth sufficient pam_unix.so
auth required pam_deny.so
account required pam_permit.so
password required pam_deny.so
session required pam_permit.so
to:
# login: auth account password session
auth optional pam_krb5.so
auth optional pam_mount.so
auth sufficient pam_serialnumber.so serverinstall legacy
auth required pam_opendirectory.so
account required pam_nologin.so
account required pam_opendirectory.so
password required pam_deny.so
session required pam_uwtmp.so
session optional pam_mount.so
Needs further investigation as to what is the 'minimum' we can get away with
changing... A little testing shows that:
auth sufficient pam_securityserver.so
auth sufficient pam_unix.so
replaced with:
auth sufficient pam_opendirectory.so
Is enough. This should be tested for compatibility with at least 10.4, and
maybe 10.4
|