Re: Forcing new password at login (w/o requiring an old password) (sudo related)
From: Richard E. Silverman (res_at_qoxp.net)
Date: 08/23/05
- Next message: dwalin: "Re: putty's telnet.c fix"
- Previous message: Darren Dunham: "Re: Forcing new password at login (w/o requiring an old password) (sudo related)"
- In reply to: Andrew Gideon: "Forcing new password at login (w/o requiring an old password) (sudo related)"
- Next in thread: Andrew Gideon: "Re: Forcing new password at login (w/o requiring an old password) (sudo related)"
- Reply: Andrew Gideon: "Re: Forcing new password at login (w/o requiring an old password) (sudo related)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 22 Aug 2005 22:20:36 -0400
>>>>> "AG" == Andrew Gideon <c182driver@gideon.org> writes:
AG> With SSH, we can have someone create a keypair for their new
AG> account, send us the public key, and they've the ability to log
AG> in. No passwords exchanged, no security issues.
There are security issues nonetheless. Unless you use strong
authentication on the email (e.g. GPG, S/MIME), you don't know who sent
it. Anyone could send you a public key, forging the email address of
someone with a new account from whom you're expecting a message.
And if you've done the prerequisite work to enable secure email, you could
just as well use it to send a password securely. Now, SSH publickey
authentication has several advantages over passwords per se, but that's a
separate issue.
-- Richard Silverman res@qoxp.net
- Next message: dwalin: "Re: putty's telnet.c fix"
- Previous message: Darren Dunham: "Re: Forcing new password at login (w/o requiring an old password) (sudo related)"
- In reply to: Andrew Gideon: "Forcing new password at login (w/o requiring an old password) (sudo related)"
- Next in thread: Andrew Gideon: "Re: Forcing new password at login (w/o requiring an old password) (sudo related)"
- Reply: Andrew Gideon: "Re: Forcing new password at login (w/o requiring an old password) (sudo related)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|