[OpenAFS] AFS token, SSH, KRB[5]

2007-06-07 Thread Rainer Laatsch
Interested parties might want to have a look at /afs/rrz.uni-koeln.de/vol/pam/pam_runexec.tar The pam_runexec is configurable to get a token by executing [KRB4] klog+afslog or [KRB5] kinit+gssklog under pam. Config's are included. In auth, a pag is set, and a session based ticket file is also

Re: [OpenAFS] Switching from MIT to win 2003 krb5 server - ktpass question

2007-06-07 Thread Lars Schimmer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi! Now I tried to export [EMAIL PROTECTED] via ktpass on Win 2003 AD Server. I used the line: ktpass -out NAME.out.txt -princ [EMAIL PROTECTED] \ -crypto DES-CBC-CRC +rndPass -DesOnly /ptype KRB5_NT_SRV_HST Was thsi correct? in the old mails

[OpenAFS] compile error on AIX 5.3 - softsig.c

2007-06-07 Thread adke
Get this error while compiling on AIX 5.3. Maybe I gave more information than needed, and any help will be appreciated. Thanks ahead of time. /openafs/openafs-1.4.4/src/pinstall/pinstall libafsauthent.a /openafs/op enafs-1.4.4/lib/libafsauthent.a Target all is up to date.

Re: [OpenAFS] compile error on AIX 5.3 - softsig.c

2007-06-07 Thread Derrick J Brashear
On Thu, 7 Jun 2007 [EMAIL PROTECTED] wrote: Get this error while compiling on AIX 5.3. Maybe I gave more information than needed, and any help will be appreciated. Thanks ahead of time. DRXDEBUG -c ../util/softsig.c ../util/softsig.c, line 93.26: 1506-099 (S) Unexpected argument. which

Re: [OpenAFS] compile error on AIX 5.3 - softsig.c

2007-06-07 Thread adke
It takes set and sig, so I guess I should change that in softsig.c. Thanks! On Thu, 7 Jun 2007 10:05:37 -0400 (EDT) Derrick J Brashear [EMAIL PROTECTED] wrote: On Thu, 7 Jun 2007 [EMAIL PROTECTED] wrote: Get this error while compiling on AIX 5.3. Maybe I gave more information than

Re: [OpenAFS] compile error on AIX 5.3 - softsig.c

2007-06-07 Thread Derrick J Brashear
On Thu, 7 Jun 2007 [EMAIL PROTECTED] wrote: It takes set and sig, so I guess I should change that in softsig.c. Thanks! um, guess what? sigwait(ss, sigw); sigset_t ss int sigw; which are set and sig. I smell conflicting macros. On Thu, 7 Jun 2007 10:05:37 -0400 (EDT)

[OpenAFS] SGE and AFS

2007-06-07 Thread Dj Merrill
Hi all, Does anyone know where there might be instructions on setting up SGE (Sun Grid Engine) 6.1 http://www.sun.com/software/gridware/index.xml to integrate with AFS and Krb 5? Thanks, -Dj -- Dj Merrill Department of Economics Unix Infrastructure

Re: [OpenAFS] SGE and AFS

2007-06-07 Thread Douglas E. Engert
Dj Merrill wrote: Hi all, Does anyone know where there might be instructions on setting up SGE (Sun Grid Engine) 6.1 http://www.sun.com/software/gridware/index.xml to integrate with AFS and Krb 5? http://www.lions.odu.edu:8080/hpcdocs/SMP-Environment/SGE/Overview Talks about using

Re: [OpenAFS] AFS token, SSH, KRB[5]

2007-06-07 Thread Russ Allbery
Rainer Laatsch [EMAIL PROTECTED] writes: Interested parties might want to have a look at /afs/rrz.uni-koeln.de/vol/pam/pam_runexec.tar The pam_runexec is configurable to get a token by executing [KRB4] klog+afslog or [KRB5] kinit+gssklog under pam. Config's are included. In auth, a pag is

Re: [OpenAFS] AFS token, SSH, KRB[5]

2007-06-07 Thread Christof Hanke
Russ Allbery wrote: Rainer Laatsch [EMAIL PROTECTED] writes: Interested parties might want to have a look at /afs/rrz.uni-koeln.de/vol/pam/pam_runexec.tar The pam_runexec is configurable to get a token by executing [KRB4] klog+afslog or [KRB5] kinit+gssklog under pam. Config's are

Re: [OpenAFS] SGE and AFS

2007-06-07 Thread Wolfgang Friebel
On Thu, 7 Jun 2007, Douglas E. Engert wrote: Dj Merrill wrote: Hi all, Does anyone know where there might be instructions on setting up SGE (Sun Grid Engine) 6.1 http://www.sun.com/software/gridware/index.xml to integrate with AFS and Krb 5?

[OpenAFS] cgi and afs?

2007-06-07 Thread Zach
I was talking to our sys admin. about allowing us users to run cgi programs from our afs accounts (served from $HOME/www which has system:anyuser rl) and asked if the web server could do this and was told first that the CMU AFS team was working on a way to make CGI principles for andrew (AFS

Re: [OpenAFS] SGE and AFS

2007-06-07 Thread Dj Merrill
http://www.lions.odu.edu:8080/hpcdocs/SMP-Environment/SGE/Overview Talks about using SGE and OpenAFS. You can also have a look at http://dvinfo.ifh.de/SGEwithAFS Thanks, all. I also ran across http://www.lrz-muenchen.de/services/hpc/linux-cluster/lxadmin/job-control.html

Re: [OpenAFS] cgi and afs?

2007-06-07 Thread Christopher D. Clausen
Zach [EMAIL PROTECTED] wrote: Is there a canonical way for a user to tell which version of AFS is running? I always tell people to use rxdebug to figure out what AFS version they are running. C:\rxdebug localhost 7001 -version Trying 127.0.0.1 (port 7001): AFS version: OpenAFS1.5.2000 You

Re: [OpenAFS] compile error on AIX 5.3 - softsig.c

2007-06-07 Thread Tom Keiser
On 6/7/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Get this error while compiling on AIX 5.3. Maybe I gave more information than needed, and any help will be appreciated. Thanks ahead of time. /openafs/openafs-1.4.4/src/pinstall/pinstall libafsauthent.a /openafs/op

Re: [OpenAFS] AFS token, SSH, KRB[5]

2007-06-07 Thread Russ Allbery
Christof Hanke [EMAIL PROTECTED] writes: Russ Allbery wrote: Out of curiosity, what did you find was missing from existing PAM modules that led you to write your own? Out of curiosity, you're american I assume, so why does the concept of competition rises interest ? I'm not quite sure what

Re: [OpenAFS] AFS token, SSH, KRB[5]

2007-06-07 Thread Jeff Blaine
Russ Allbery wrote: Christof Hanke [EMAIL PROTECTED] writes: Russ Allbery wrote: Out of curiosity, what did you find was missing from existing PAM modules that led you to write your own? Out of curiosity, you're american I assume, so why does the concept of competition rises interest ?

[OpenAFS] Re: vos dump authorization based on bos adduser?

2007-06-07 Thread Adam Megacz
Derrick J Brashear [EMAIL PROTECTED] writes: Actually, now that I think about it, if all the ptserver instances are down, how would an admin be able to aklog (in order to run bos commands)? -localauth. (but aklog doesn't *require* ptserver; see afslog) But localauth doesn't even require the

Re: [OpenAFS] Re: vos dump authorization based on bos adduser?

2007-06-07 Thread Derrick J Brashear
On Thu, 7 Jun 2007, Adam Megacz wrote: Derrick J Brashear [EMAIL PROTECTED] writes: Actually, now that I think about it, if all the ptserver instances are down, how would an admin be able to aklog (in order to run bos commands)? -localauth. (but aklog doesn't *require* ptserver; see

[OpenAFS] Re: cgi and afs?

2007-06-07 Thread Adam Megacz
Zach [EMAIL PROTECTED] writes: Curious if Open AFS already has a way to do this or plans on implementing it. I think CMU is running special in-house customized AFS. You want the WaklogPrincipal directive in UMBC's mod_waklog. http://www.umbc.edu/oit/iss/syscore/wiki/Mod_waklog Works quite

[OpenAFS] Re: Switching from MIT to win 2003 krb5 server

2007-06-07 Thread Adam Megacz
FWIW, this is easy (easier?) if you set up an empty realm with no users and an MIT KDC just for the AFS cell, and establish cross-realm trust between the two KDCs. I'm doing this at the moment against two AD realms on campus (one Win2k0, one Win2k3) and it works quite well. It also minimizes

Re: [OpenAFS] Re: cgi and afs?

2007-06-07 Thread Derrick J Brashear
On Thu, 7 Jun 2007, Adam Megacz wrote: Zach [EMAIL PROTECTED] writes: Curious if Open AFS already has a way to do this or plans on implementing it. I think CMU is running special in-house customized AFS. You want the WaklogPrincipal directive in UMBC's mod_waklog.