Henry B. Hotz wrote: > Second (or is that tenth?). ;-) > > Also want pam_krb5 to be configurable to require a smart card with > PKINIT.
For info in PKINIT ask on kerberos-discuss at opensolaris.org. > Then a plausible use case is to put both in as sufficient. > (Then we worry about whether we can get rid of everything that *doesn't* > use a smart card.) Why would you use both a pam_krb5 that is ware of PKINIT and pam_pkcs11? -- Darren J Moffat