<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
Sorry. I meant GSSAPI login.<br>
<br>
Jem<br>
<br>
<br>
Simo Sorce wrote:
<blockquote cite="mid:1223483414.632.28.camel@hopeson" type="cite">
<pre wrap="">On Wed, 2008-10-08 at 11:07 -0500, <a class="moz-txt-link-abbreviated" href="mailto:puck@i29.net">puck@i29.net</a> wrote:
</pre>
<blockquote type="cite">
<pre wrap="">I've run into a problem when setting up IPA for ssh logins. I've found
that I need to set ChallengeResponseAuthentication to "yes" in my
sshd_config to allow users to change their expired passwords on login,
otherwise the login process just hangs and eventually times out.
However, when I set it to "yes" password-less logins between my servers
no longer work. Once I'm logged in, if I run a "kinit (username)" then
the password-less login works again so I assume that when
ChallengeResponseAuthentication is on, sshd just doesn't set that
correctly. Can anyone recommend an sshd configuration that would allow
both the password-less logins and allow users to change their passwords
at login when they are expired?
</pre>
</blockquote>
<pre wrap=""><!---->
By "password-less" login you mean a gssapi login or an ssh-key aided
login ?
Simo.
</pre>
</blockquote>
</body>
</html>