Samba 2.2.X, PAM and Kerberos5

Bogdan Iamandei bogdan at
Wed May 15 17:59:01 GMT 2002

Steve Langasek wrote:
> As far as it goes, your above configuration looks correct.  Have you
> checked wherever your syslog auth  facility logs to, to see if pam_krb5
> is logging any information that might be useful?

Hmm, although it seems it supports the "debug" switch, the module seems 
mute as a fish.

> Are you using the Solaris pam_krb5 module, or a third-party module?

The "original" (apparently in more than one way) Solaris module. I'll be 
compiling and packaging the MIT kerberos today and then try the whole 
thing against that one. I'll let you know how this goes.

> I'm not sure why the 'appdata_ptr == NULL' check is there, but I seem to
> remember that it's true that Solaris does not honor the appdata_ptr
> field.  If Samba now depends on sane handling of appdata_ptr, then it's
> likely that this won't work on Solaris.

Grrr!! wonderful. Mkay then, I think that this little Solaris 
(mis)feature would be nice to be at least mentioned somewhere in the 
docs, in case some other masochist considers going down this path. :)


I have seen things you people wouldn't believe.  Attack ships on fire
off the shoulder of Orion.  I watched C-beams glitter in the dark
near the Tannhauser Gate.  All those moments will be lost in time,
like tears in rain.  Time to die.

More information about the samba-technical mailing list