Subject: Netatalk + PAM on RedHat 6.2
From: Alexi Margo (alexi@wwood.co.uk)
Date: Wed Sep 27 2000 - 08:33:29 EDT
Hi,
I am new to Netatalk, but have successfully installed it on a test machine,
running RedHat 6.2. Macintosh machines are able to connect to and use shares
correctly when connecting as "guest". The problem is that I need to
authenticate users specifically via PAM, since authentication is handled by
a Microsoft NT Domain Controller (I have successfully got PAM using this).
The problem is that despite following all the instructions in the various
FAQ's (specifically those at http://www.thehamptons.com/anders/netatalk/),
Netatalk does *not* appear to be using PAM.
> [root@miserver /root]# ldd /usr/local/atalk/etc/atalkd
> libc.so.5 => /usr/i486-linux-libc5/lib/libc.so.5 (0x4000a000)
Since atalkd is not dependant on libpam, I assume that PAM is not being used
for authentication. Attempted logins are not being logged in syslog as would
normally be the case with PAM. To summarise, the changes that I made to
netatalk-1.4b2+asun2.1.1 before compiling it were:
/Makefile:
* set variable PAMDIR to /usr
/etc/atalkd/Makefile:
* CFLAGS = ${DEFS} ${AFSDEFS} ${KRBDEFS} ${DESDEFS} ${OPTOPTS} \
${INCPATH} ${PAMDEFS} -DAPPLCNAME -DCRLF -DUSE_PAM
/sys/linux/Makefile:
* DEFS= -DNEED_QUOTACTL_WRAPPER -DUSE_PAM
* AFPLIBS=-lrpcsvc
* ADDLIBS=-lpam -ldl
If anyone could shine some light on what is going on here, it would be
greatly appreciated.
**********************************************************
Alexi Margo
Internet Systems Manager
Wildwood Technology Ltd
http://www.wwood.co.uk/
t +44-(0)20 8426 7777
f +44-(0)20 8426 5050
**********************************************************
This message is intended only for the use of the person(s) ("the Intended
Recipient") to whom it is addressed. It may contain information which is
privileged and confidential within the meaning of applicable law.
Accordingly any dissemination, distribution, copying or other use of this
message or any of its content by any person other than the Intended
Recipient may constitute a breach of civil or criminal law and is strictly
prohibited. If you are not the Intended Recipient please contact the sender
as soon as possible.
This archive was generated by hypermail 2b28 : Wed Jan 17 2001 - 14:32:14 EST