• configuring libkadm5clnt_mit/libkadm5 for NIS password migration in Fed

    From Robert Kudyba@21:1/5 to All on Mon Nov 9 16:45:35 2020
    I posted a few weeks back about migrating our NIS user passwords and
    the response
    I got was <https://mailman.mit.edu/pipermail/kerberos/2020-October/022559.html>:
    "In Fedora, libkadm5clnt_mit.so is provided by libkadm5. Please be aware
    that neither I (Fedora maintainer) do not support external programs using
    the libkadm5 interface."

    I'm trying to determine how to configure PAM to get this password migration library to work. I posted on Reddit <https://www.reddit.com/r/sysadmin/comments/jmxf6w/migrating_nis_password_to_kerberos_on_fedorared/>,
    to no avail.

    What needs to go in /etc/authselect/password-auth and/or /etc/authselect/system-auth? I tried putting:
    auth optional pam_krb5_migrate.so.1 expire_pw

    But I get this error:

    debug1: PAM: initializing for "myuser" PAM unable to resolve symbol: pam_sm_authenticate PAM unable to resolve symbol: pam_sm_setcred

    Any guidance would be greatly appreciated.



    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)