Use pam_krb5 instead of the built in GSSAPI support. The only reason that 
option is there is for UNIX platforms that don't support PAM such as AIX


Sent from my BlackBerry 10 smartphone.
  Original Message  
From: Steven Timm
Sent: Wednesday, March 11, 2015 09:58
To: [email protected]
Subject: Successful configuration for openssh 6.x and kerberos

Does anyone have a successful ssh client side configuration
for scientific linux 7 (which uses openssh 6.4) such that it
can ssh into older machines at Fermilab using Kerberos authentication?
I am needing this for a remote site which is running openssh 6.
It appears that the GSSAPIKeyExchange method
which is the preferred method in openssh 5.x clients may not
be available in openssh 6, at least not in the version the remote
site has compiled for themselves.

Steve Timm



------------------------------------------------------------------
Steven C. Timm, Ph.D (630) 840-8525
[email protected] http://home.fnal.gov/~timm/
Office: Wilson Hall room 804
Fermilab Scientific Computing Division,
Scientific Computing Facilities Quadrant.,
Experimental Computing Facilities Dept.,
Project Lead for Virtual Facility Project.

Reply via email to