Craig Gallek <[EMAIL PROTECTED]> writes: > pam_krb5.so doesn't appear to be used when > ChallengeResponseAuthentication is set to no. Only pam_unix.so is used.
Oh, also, note that the new module correctly separates authentication and session management (so that it will work correctly with xlock programs, among other reasons), which means that you do have to run the krb5 PAM module in the session section as well as auth, passing it the same arguments as you would for auth. -- Russ Allbery ([EMAIL PROTECTED]) <http://www.eyrie.org/~eagle/> -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]