Mon, 19 Dec 2005

OpenSSH + gssapi + kerberos + afs happy dance, on NetBSD 3.0 RC6

Server:

Log in with an appropriately smart ssh client where you have forwardable kerberos credentials. "Appropriately smart" means "understands gssapi-with-mic and actually tries to do it" --- see the previous entry for details on that. See the client configurations listed here. The afslog in sshrc allows you to get afs tokens when you login via gssapi-with-mic --- the forwarded kerberos credentials are just plopped down, and aren't used to automatically get afs tokens.

Neatly, I noticed that console logins Just Work. Spiffy.

Posted at: 23:59 | category: /pn/ssh | Link

Thu, 15 Dec 2005

OpenSSH + gssapi + kerberos + afs happy dance

Server:

Client:

Posted at: 01:15 | category: /pn/ssh | Link