Re: Force non-empty pass-phrase?
- From: "Richard E. Silverman" <res@xxxxxxxx>
- Date: 27 Apr 2006 00:52:27 -0400
"mark" == mark <mark@xxxxxxxxxx> writes:
mark> Does anybody know of a way to enforce a policy where ssh key
mark> pass-phrases should not be empty? It is one of the "weaknesses"
mark> of ssh as I see it that an administrator can't actually impose
mark> this constraint on access to his own server.
He can't, because it makes no sense. The server never sees the user's
private key. It has no control over where or how the key is stored. It's
like suggesting there's a lock out there that can "require" that you not
keep the key in your pocket.
--
Richard Silverman
res@xxxxxxxx
.
- Follow-Ups:
- Re: Force non-empty pass-phrase?
- From: mark
- Re: Force non-empty pass-phrase?
- From: Nico Kadel-Garcia
- Re: Force non-empty pass-phrase?
- References:
- Force non-empty pass-phrase?
- From: mark
- Force non-empty pass-phrase?
- Prev by Date: Force non-empty pass-phrase?
- Next by Date: openssh 4.3p2 connection closed problem
- Previous by thread: Force non-empty pass-phrase?
- Next by thread: Re: Force non-empty pass-phrase?
- Index(es):
Relevant Pages
|
|