Dear Maintainer,
Please find attached a patch to allow openssh to reject GSS-API
authentication (and fall-through to the next mechanism, usually
keyboard-interactive) if Kerberos tickets are not being
delegated. This features is controlled by a default-off configuration
option, and does not affect any defaults.
This is useful for sites that deploy openafs, as it requires users to
either delegate tickets or enter their password, gaining access to
their files in AFS. This patch is currently deployed at MIT.
The patch is also available online at
http://mit.edu/achernya/www/openssh-optionally-require-forwarded-tickets.diff
Sincerely,
-Alex