Use pam_krb5 instead of the built in GSSAPI support. The only reason that option is there is for UNIX platforms that don't support PAM such as AIX
Sent from my BlackBerry 10 smartphone. Original Message From: Steven Timm Sent: Wednesday, March 11, 2015 09:58 To: [email protected] Subject: Successful configuration for openssh 6.x and kerberos Does anyone have a successful ssh client side configuration for scientific linux 7 (which uses openssh 6.4) such that it can ssh into older machines at Fermilab using Kerberos authentication? I am needing this for a remote site which is running openssh 6. It appears that the GSSAPIKeyExchange method which is the preferred method in openssh 5.x clients may not be available in openssh 6, at least not in the version the remote site has compiled for themselves. Steve Timm ------------------------------------------------------------------ Steven C. Timm, Ph.D (630) 840-8525 [email protected] http://home.fnal.gov/~timm/ Office: Wilson Hall room 804 Fermilab Scientific Computing Division, Scientific Computing Facilities Quadrant., Experimental Computing Facilities Dept., Project Lead for Virtual Facility Project.
