>Fedora DS does not support the {KERBEROS}user at REALM method in the >userPassword attribute. That is an OpenLDAP only feature, AFAIK. Ah, well that makes my life easy! >> Another more general question. As I want to use the passthrough module strictly to do the the Kerberos logins, I assume the 'ldapserver' pam file would only need pam_krb5.so and not, for example, pam_unix.so. Is that right? >> >I think so, but I'm not sure. You'll have to ask a PAM guru for that. If anyone has pointers, please let me know. Thanks! Marty