libpam-afs-session - PAM module to set up a PAG and obtain AFS tokens

Property Value
Distribution Debian 8 (Jessie)
Repository Debian Main amd64
Package name libpam-afs-session
Package version 2.5
Package release 4
Package architecture amd64
Package type deb
Installed size 123 B
Download size 40.66 KB
Official Mirror
AFS is a distributed network file system.  It uses in-kernel credentials
(AFS tokens) obtained from Kerberos tickets for authentication and access
control, and controls access to those credentials via PAGs (process
authentication groups).  This module provides a PAM session
implementation that puts new logins in separate PAGs and optionally runs
an external program (usually aklog) to obtain tokens from Kerberos
tickets.  It is designed to work with a Kerberos PAM module that obtains
the initial Kerberos tickets.


Package Version Architecture Repository
libpam-afs-session_2.5-4_i386.deb 2.5 i386 Debian Main
libpam-afs-session - - -


Name Value
libc6 >= 2.14
libkrb5-3 >= 1.6.dfsg.2
libpam-runtime >= 1.0.1-6~
libpam0g >= 1.1.3-2~
multiarch-support -


Type URL
Binary Package libpam-afs-session_2.5-4_amd64.deb
Source Package libpam-afs-session

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install libpam-afs-session deb package:
    # sudo apt-get install libpam-afs-session




2014-04-13 - Russ Allbery <>
libpam-afs-session (2.5-4) unstable; urgency=medium
* Remove now-unnecessary dh_builddeb override to force xz compression.
* Convert debian/copyright to copyright-format 1.0.
* Specify the Debian packaging branch in the Vcs-Git control field.
* Add the upstream release signing key and verify it in debian/watch.
* Update standards version to 3.9.5 (no changes required).
2013-06-23 - Russ Allbery <>
libpam-afs-session (2.5-3) unstable; urgency=low
* Apply upstream patch to add AM_PROG_AR to, now apparently
required by Automake for the binutils in unstable.  (Closes: #713292)
* Apply upstream patch to build with largefile support.  This is
probably pointless for this module, but consistency is good.
* Switch to xz compression for the binary package and *.debian.tar file.
* Enable parallel builds.
* Canonicalize the Vcs-Git and Vcs-Browser URLs.
* Update standards version to 3.9.4 (no changes required).
2012-02-06 - Russ Allbery <>
libpam-afs-session (2.5-2) unstable; urgency=low
* Enable bindnow hardening flags.
* Change the architecture of the package to linux-any, since there is no
OpenAFS support for the FreeBSD kernel yet.
* Bump debhelper dependency to 9 now that compatibility mode V9 is no
longer experimental.
* Regenerate the Autotools build system with dh-autoreconf.
* Move single-debian-patch to local-options and patch-header to
local-patch-header so that they only apply to the packages I build and
NMUs get regular version-numbered patches.
2011-07-25 - Russ Allbery <>
libpam-afs-session (2.5-1) unstable; urgency=low
* New upstream release.
- Reset the SIGCHLD handler while spawning an external aklog program
so that the application SIGCHLD handler isn't invoked when aklog
exits.  (Closes: #630609)
* Convert to multiarch.  Depend on the multiarch version of
libpam0g, install the module into the multiarch version of
/lib/security, and declare the package Multi-Arch: same.
* Update to debhelper compatibility level V9 (experimental).
- Build-Depend on debhelper 8.1.3 or later.
- Add Pre-Depends: ${misc:Pre-Depends}.
- Add Lintian override for using an experimental debhelper level.
* Remove unnecessary debian/dirs file.
2011-06-08 - Russ Allbery <>
libpam-afs-session (2.4-1) unstable; urgency=low
* New upstream release.
- Fix memory allocation bug in the previous release.
2011-06-07 - Russ Allbery <>
libpam-afs-session (2.3-1) unstable; urgency=low
* New upstream release.
- Honor KRB5CCNAME from the general environment if it is set and that
variable is not set in the PAM environment, rather than declining to
run aklog.  (Closes: #621496)
* Update standards version to 3.9.2 (no changes required).
2011-03-03 - Russ Allbery <>
libpam-afs-session (2.2-1) unstable; urgency=low
* New upstream release.
- Return PAM_SUCCESS instead of PAM_IGNORE from pam_setcred if AFS is
not available or if we're deleting credentials but the PAM module is
configured not to delete tokens.  Returning PAM_IGNORE from
pam_setcred confuses the Linux PAM library.
- Fix error return statuses for pam_setcred.
2011-01-23 - Russ Allbery <>
libpam-afs-session (2.1-1) experimental; urgency=low
* New upstream release.
- The program option can now pass arguments to aklog by separating
them with spaces, tabs, or commas (commas are most useful in the PAM
configuration files).
- Paths to aklog containing spaces or commas are no longer supported.

See Also

Package Description
libpam-alreadyloggedin_0.3-6_amd64.deb PAM module to skip password authentication for logged users
libpam-apparmor_2.9.0-3_amd64.deb changehat AppArmor library as a PAM module
libpam-barada_0.5-3.1+b2_amd64.deb PAM module to provide two-factor authentication based on HOTP
libpam-blue_0.9.0-3_amd64.deb PAM module for local authenticaction with bluetooth devices
libpam-cap_2.24-8_amd64.deb POSIX 1003.1e capabilities (PAM module)
libpam-ccreds_10-6+b2_amd64.deb Pam module to cache authentication credentials
libpam-cgroup_0.41-6_amd64.deb control and monitor control groups (PAM)
libpam-chroot_0.9-4.1_amd64.deb Chroot Pluggable Authentication Module for PAM
libpam-ck-connector_0.4.6-5_amd64.deb ConsoleKit PAM module
libpam-cracklib_1.1.8-3.1+deb8u2+b1_amd64.deb PAM module to enable cracklib support
libpam-dbus_0.2.1-3_amd64.deb A PAM module which asks the logged in user for confirmation
libpam-doc_1.1.8-3.1+deb8u2_all.deb Documentation of PAM
libpam-duo_1.9.11-1_amd64.deb PAM module for Duo Security two-factor authentication
libpam-dynalogin_1.0.0-3+b1_amd64.deb two-factor HOTP/TOTP authentication - implementation libs
libpam-encfs_0.1.4.4-7_amd64.deb PAM module to automatically mount encfs filesystems on login