Skip site navigation (1)Skip section navigation (2)
Date:      19 Jun 2002 11:39:51 +0200
From:      Dag-Erling Smorgrav <des@ofug.org>
To:        Ryan Thompson <ryan@sasknow.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: Password security
Message-ID:  <xzpn0trip3s.fsf@flood.ping.uio.no>
In-Reply-To: <20020618204711.I65632-100000@ren.sasknow.com>
References:  <20020618204711.I65632-100000@ren.sasknow.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Ryan Thompson <ryan@sasknow.com> writes:
> So, given the limitations of remote access (from machines assumed to
> be insecure), and some fairly dumb Windows clients, what are some
> solutions to password security?

You need a challenge/response-based authentication mechanism.  If your
users all have PDAs, you can use OPIE (provided you can find or write
an OPIE calculator that will run on their PDAs); or you can use
CRYPTOCard tokens.  The server software runs on Windows and Linux (I'm
working on getting the Linux version to run on FreeBSD); all you need
on the FreeBSD side is pam_radius.

DES
-- 
Dag-Erling Smorgrav - des@ofug.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?xzpn0trip3s.fsf>