Re: john the ripper for private keys?

From: Bernd Schubert (bernd-schubert_at_web.de)
Date: 03/15/04

  • Next message: Richard E. Silverman: "Re: john the ripper for private keys?"
    Date: Mon, 15 Mar 2004 23:00:50 +0100
    
    

    >
    >>Actually I think it would be pretty easy to make ssh-add and ssh-agent not
    >>to like empty or too easy passwords as default (the same way as most
    >>passwd's currently do).
    >
    > How will you ensure people use your version of those programs ?
    > Access control belongs on the server.
    >

    Of course every version should have those tests. Users who use weak
    passwords usually don't patch programs to be able to use weak passwords, do
    they? ;)

    I think using the ssh-agent is a good way to be able to type one's password
    only once. However it can be pretty insecure since users can have weak or
    even empty passwords for their keys. I'm just looking for a way to ensure
    our users have proper passwords.

    Bernd


  • Next message: Richard E. Silverman: "Re: john the ripper for private keys?"

    Relevant Pages

    • Re: gdm login without password
      ... > Is there any functionality in gdm that allows users with empty ... I just want users with empty passwords to be able ... > which gdm doesn't let me do in its default configuration (I'm using gdm ...
      (Debian-User)
    • john the ripper for private keys?
      ... I would like to check the private keys of all users for empty or too easy ... Actually I think it would be pretty easy to make ssh-add and ssh-agent not ... to like empty or too easy passwords as default (the same way as most ...
      (comp.security.ssh)
    • Cant store passwords for external share point portal (NTLM)
      ... we're having a problem getting IE to remember the passwords ... for a share-point portal site that's on another location ... Strangely enough the username does appear under WindowsXP ... password there and click ok and return it will be empty again. ...
      (microsoft.public.windows.inetexplorer.ie6.setup)
    • gdm login without password
      ... Is there any functionality in gdm that allows users with empty ... I just want users with empty passwords to be able ...
      (Debian-User)
    • Re: Minimum password requirements
      ... Passwords must be changed at least every 90 days. ... easy passwords, or write them down if they're forced to change so ... Personally, I'm all for it but I'm interested in security, ... whereas the average user wants to be inconvenienced as little as ...
      (Security-Basics)