From owner-freebsd-security@FreeBSD.ORG Thu Dec 11 09:25:46 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 746A216A4CF for ; Thu, 11 Dec 2003 09:25:46 -0800 (PST) Received: from mail.fmi.unibuc.ro (fmi.unibuc.ro [193.226.51.6]) by mx1.FreeBSD.org (Postfix) with ESMTP id 94CB843D2C for ; Thu, 11 Dec 2003 09:25:44 -0800 (PST) (envelope-from radu@fmi.unibuc.ro) Received: from localhost (localhost [127.0.0.1]) by mail.fmi.unibuc.ro (Postfix) with ESMTP id DCF62E268; Thu, 11 Dec 2003 19:27:23 +0200 (EET) Received: from mail.fmi.unibuc.ro ([127.0.0.1]) by localhost (mail.fmi.unibuc.ro [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 08677-02; Thu, 11 Dec 2003 19:27:23 +0200 (EET) Received: from fmi.unibuc.ro (unknown [192.168.0.1]) by mail.fmi.unibuc.ro (Postfix) with SMTP id DBFBDE266; Thu, 11 Dec 2003 19:27:22 +0200 (EET) Received: from 193.226.51.11 (SquirrelMail authenticated user radu) by fmi.unibuc.ro with HTTP; Thu, 11 Dec 2003 19:26:30 +0200 (EET) Message-ID: <33200.193.226.51.11.1071163590.squirrel@fmi.unibuc.ro> In-Reply-To: <20031211073336.GO57995@zeus.theinternet.com.au> References: <6.0.0.22.2.20031210115335.04c2fc50@localhost><20031210093927.70c87960 .amonk@gnutec.com><6.0.0.22.2.20031210124332.04e94ac0@localhost><16343 .33321.632599.190251@oscar.buszard-welcher.com><6.0.0.22.2.20031210173 916.04f57be8@localhost> <3FD7C240.4030005@tenebras.com><6.0.0.22.2.20031210193940.04f82c20@loc alhost> <20031211073336.GO57995@zeus.theinternet.com.au> Date: Thu, 11 Dec 2003 19:26:30 +0200 (EET) From: "Radu-Mihail Obada" To: "Andrew Kenneth Milton" User-Agent: SquirrelMail/1.4.0 MIME-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 X-Priority: 3 Importance: Normal X-Virus-Scanned: by amavisd-new at fmi.unibuc.ro cc: security@freebsd.org Subject: Re: s/key authentication for Apache on FreeBSD? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: radu@fmi.unibuc.ro List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 11 Dec 2003 17:25:46 -0000 It sounds like an excellent idea to me. And you get the added bonus of encryption. Nice thinking, Brett. > Why don't you issue certificates to each user, that have a fixed life > span, > say a week (or day or a few hours), and avoid the password thing > altogether? -- Radu "Daemon" Obada, Faculty of Mathematics and Computer Science, University of Bucharest