[38838] in Kerberos

home help back first fref pref prev next nref lref last post

configuring libkadm5clnt_mit/libkadm5 for NIS password migration in

daemon@ATHENA.MIT.EDU (Robert Kudyba)
Mon Nov 9 16:48:51 2020

MIME-Version: 1.0
From: Robert Kudyba <rkudyba@fordham.edu>
Date: Mon, 9 Nov 2020 16:45:35 -0500
Message-ID: <CAFHi+KSwFe3TvodoCOED_-Uit68625Jy6Y7UZFYwv9=dpjnz6A@mail.gmail.com>
To: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

I posted a few weeks back about migrating our NIS user passwords and
the response
I got was
<https://mailman.mit.edu/pipermail/kerberos/2020-October/022559.html>:
"In Fedora, libkadm5clnt_mit.so is provided by libkadm5. Please be aware
that neither I (Fedora maintainer) do not support external programs using
the libkadm5 interface."

I'm trying to determine how to configure PAM to get this password migration
library to work. I posted on Reddit
<https://www.reddit.com/r/sysadmin/comments/jmxf6w/migrating_nis_password_to_kerberos_on_fedorared/>,
to no avail.

What needs to go in /etc/authselect/password-auth and/or
/etc/authselect/system-auth? I tried putting:
auth optional pam_krb5_migrate.so.1 expire_pw

But I get this error:

debug1: PAM: initializing for "myuser" PAM unable to resolve symbol:
pam_sm_authenticate PAM unable to resolve symbol: pam_sm_setcred

Any guidance would be greatly appreciated.

Thanks.

Rob
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post