libpam-krb5 - PAM module for MIT Kerberos

Property Value
Distribution Debian 8 (Jessie)
Repository Debian Main amd64
Package name libpam-krb5
Package version 4.6
Package release 3+b1
Package architecture amd64
Package type deb
Installed size 128 B
Download size 81.52 KB
Official Mirror
A Kerberos PAM module build against the MIT Kerberos libraries.  It
supports authenticating against a Kerberos v5 KDC, obtaining tickets and
populating an initial ticket cache, authorizing users via a ~/.k5login
file, and changing Kerberos passwords.


Package Version Architecture Repository
libpam-krb5_4.6-3+b1_i386.deb 4.6 i386 Debian Main
libpam-krb5 - - -


Name Value
krb5-config -
libc6 >= 2.14
libkrb5-3 >= 1.10.2+dfsg
libpam-runtime -
libpam0g >= 1.1.3-2~
multiarch-support -


Name Value
libpam-heimdal -


Type URL
Binary Package libpam-krb5_4.6-3+b1_amd64.deb
Source Package libpam-krb5

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install libpam-krb5 deb package:
    # sudo apt-get install libpam-krb5




2014-04-13 - Russ Allbery <>
libpam-krb5 (4.6-3) unstable; urgency=medium
* Drop version qualifications on Build-Depends that are satisfied by
stable.  Drop version qualifications on Depends that are satisfied by
* Add the upstream release signing key and verify it in debian/watch.
* Prefer *.tar.xz in debian/watch to match packaging.
* Convert debian/copyright to copyright-format 1.0.
* Specify the Debian packaging branch in the Vcs-Git control field.
* Update standards version to 3.9.5 (no changes required).
2013-06-23 - Russ Allbery <>
libpam-krb5 (4.6-2) unstable; urgency=low
* Apply upstream patch to add AM_PROG_AR to, now apparently
required by Automake for the binutils in unstable.  (Closes: #713296)
* Apply upstream patch to build with largefile support.  This is
probably pointless for this module, but consistency is good.
* Canonicalize the Vcs-Git and Vcs-Browser URLs.
* Update standards version to 3.9.4 (no changes required).
2012-06-02 - Russ Allbery <>
libpam-krb5 (4.6-1) unstable; urgency=low
* New upstream release.
- New anon_fast option to attempt anonymous authentication and use
those credentials to provide FAST armor.  (Closes: #626509)
- New user_realm option to set the realm for unqualified user
principals without changing the default realm for all other
- New no_prompt option to suppress PAM prompting in favor of letting
the Kerberos library handle it.  (Closes: #626506)
- New silent option that duplicates the behavior of PAM_SILENT.
- New trace option for preliminary support of Kerberos trace logging.
- Fix the doubled colon in password prompts from Heimdal.
- Preserve the realm of the authentication identity when forming an
alt_auth_map identity.
- Allow the alt_auth_map format to contain a realm to force all mapped
principals to be in that realm.
- Avoid a NULL pointer dereference if krb5_init_context fails.
(LP: #998525)
- Close memory leaks in search_k5login and alt_auth_map.
- Suppress bogus error messages about the realm option.
- Retry authentication under try_first_pass for several other error
* Regenerate the Autotools build system with dh-autoreconf.
* Add krb5-config to Build-Depends so that the test programs don't abort
with errors about not having a Kerberos configuration.
* Switch to xz compression for the upstream and Debian tarballs.
* Enable parallel builds.
* Update standards version to 3.9.3 (no changes required).
2012-02-04 - Russ Allbery <>
libpam-krb5 (4.5-4) unstable; urgency=low
* Enable bindnow hardening flags and fix the syntax of the
* Bump debhelper dependency to 9 now that compatibility mode V9 is no
longer experimental.
* Move single-debian-patch to local-options and patch-header to
local-patch-header so that they only apply to the packages I build and
NMUs get regular version-numbered patches.
2012-01-03 - Russ Allbery <>
libpam-krb5 (4.5-3) unstable; urgency=low
* Fix build rule to not override CPPFLAGS, which deactivates some of the
options passed in by dpkg-buildflags.  Instead, use --with-krb5-lib
and --with-krb5-include to locate the Kerberos headers and libraries.
Thanks, Moritz Muehlenhoff.  (Closes: #654293)
2011-12-26 - Russ Allbery <>
libpam-krb5 (4.5-2) unstable; urgency=low
* Cherry-pick upstream patch to fix initialization of krb5_deltat
defaults on systems where krb5_deltat is not a long.  Should fix FTBFS
on s390x.

See Also

Package Description
libpam-ldap_184-8.7+b1_amd64.deb Pluggable Authentication Module for LDAP
libpam-ldapd_0.9.4-3+deb8u2_amd64.deb PAM module for using LDAP as an authentication service
libpam-mklocaluser_0.10_all.deb Configure PAM to create a local user if it do not exist already
libpam-modules-bin_1.1.8-3.1+deb8u2+b1_amd64.deb Pluggable Authentication Modules for PAM - helper binaries
libpam-modules_1.1.8-3.1+deb8u2+b1_amd64.deb Pluggable Authentication Modules for PAM
libpam-mount_2.14-1.1_amd64.deb PAM module that can mount volumes for a user session
libpam-mysql_0.7~RC1-4+b3_amd64.deb PAM module allowing authentication from a MySQL server
libpam-nufw_2.4.3-3.1_amd64.deb The authenticating firewall [PAM module]
libpam-oath_2.4.1-1_amd64.deb OATH Toolkit libpam_oath PAM module
libpam-ocaml-dev_1.1-4+b4_amd64.deb OCaml bindings for the PAM library (development files)
libpam-ocaml_1.1-4+b4_amd64.deb OCaml bindings for the PAM library (runtime)
libpam-openafs-kaserver_1.6.9-2+deb8u7_amd64.deb AFS distributed filesystem kaserver PAM module
libpam-otpw_1.3-2_amd64.deb Use OTPW for PAM authentication
libpam-p11_0.1.5-4_amd64.deb PAM module for using PKCS#11 smart cards
libpam-passwdqc_1.3.0-1_amd64.deb PAM module for password strength policy enforcement