HP-UX 11i June 2001 Release Notes
HP-UX 11i Operating Environment Applications
HP-UX 11i Operating Environment (new at 11i original release)
Chapter 4 83
available without modifying the application or rebooting the system.
PAM Kerberos works on HP 9000 servers and HP workstations or with a
minimum of 32MB of memory and sufficient swap space (a minimum of
50MB is recommended).
NOTE PAM Kerberos is not thread safe.
Coexistence Issues
PAM Kerberos (libpam_krb5.1) and PAM DCE (libpam_dce.1) plug-in
modules can not be stacked together in the pam.conf file because of
different principal styles and credential file paths. If so stacked, the
results will be unpredictable.
The Kerberos system ftp service may list the /etc/issue file before the
expected output. The sis (5) manpage provides detailed information. You
cannot login if the password has expired on a Microsoft Windows 2000
KDC. You will be asked for a new password but you cannot log in. This is
a known problem in Windows 2000.
When changing passwords on a MIT KDC with a version prior to 1.1, up
to 45 seconds may elapse before the password is actually changed due to
the protocol selection mechanism of the change password protocol.
Documentation
The following documentation is available:
• The newly created manpage for pam_kerberos is available at:
/usr/share/man/man5.Z/pam_krb5.5
• Network Security Features of HP-UX 11i white paper which is
available on the web at:
http://www.unix.hp.com/operating/hpux11i/infolibrary/
• PAM Kerberos Release Notes for HP-UX 11i at
http://docs.hp.com