Well peeps...
The segfault is solved, I think. I was using pamtest as a normal user with /bin/login... of course things like pam_securetty and pam_unix need to run as root, so it explains several issues. After using sudo to run pamtest, it showed a lot of success messages.
So I took the plunge, plugged it into gdm-password, and then... tried a Gnome UI login. And huzzah, it works! For local users though, I currently have two password prompts, but that makes sense because pam_gss gets an authentication failure (the local login is after all not federated and doesn't have the 'user@realm' format).
But that's a good start. I'll continue on to see how I can minimise the duplicate prompts etc.
Sorry for the goose chase, this stuff is new to me.
Stefan
|