On 11 Jun 2011, at 18:22, "Markus Moeller" <hua...@moeller.plus.com> wrote:
> If I remember right when GSSAPIauthentication is used and the client has a > valid Kerberos ticket pam won't be called on the server, so the pam module > won't help in that case. No, the PAM stack is invoked whatever mechanism has been used to authenticated the user. Russ's pam_afs_session works perfectly to add AFS tokens for users authenticated with Kerberos tickets. S. > ________________________________________________ Kerberos mailing list Kerberos@mit.edu https://mailman.mit.edu/mailman/listinfo/kerberos