otpasswd-talk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Otpasswd-talk] Using OTP to kind of fix MITM.


From: Luke Faraone
Subject: Re: [Otpasswd-talk] Using OTP to kind of fix MITM.
Date: Tue, 22 Dec 2009 16:50:21 -0500

On Tue, Dec 22, 2009 at 12:01, Tomasz bla Fortuna <address@hidden> wrote:
True. That's kind of pain. If we'd have to do it like this - checking
key location, calling some program I'd create external sh script to
the work (which can be distribution dependent) and call it to get the
fingerprint...

And if it doesn't work, we can just put up a warning "Your SSH host public key could not be automatically located. Please specify it on the command line with $SOME_OPTION if you wish your SSH fingerprint to be included on printed cards."
This can be also a pain taking into account that
otpasswd will have to be SUID to work with global database. I'd like to
implement this by 1.0, but for now there're still some things to do. ;)

Huh, SUID?   Why does there need to be a global database? Can't we just put it in ~/.otpasswd chmodded properly, like we do with SSH keys?

--
Luke Faraone
http://luke.faraone.cc

reply via email to

[Prev in Thread] Current Thread [Next in Thread]