On Mon, Jan 21, 2002 at 01:42:00 +0100, Dag-Erling Smorgrav wrote:
> 
> The admin can't enforce "always OPIE" for a user, because the user can
> always delete his ~/.opiealways.

This is per-machine choice. Long time ago, for S-KEY, it was per-terminal 
choice too, but OPIE currently not have per-terminal module.
There is no needs to enforce it for user logged from trusted machine since 
whole machine is trusted.  But paranoid users can enforce it for 
themselfs.

> How about I write a pam_opieaccess(8) module and you tell me what you
> think of it?  It's really the cleanest solution from PAM's point of
> view.

Ok, I'll write it and send for review.

-- 
Andrey A. Chernov
http://ache.pp.ru/

To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-current" in the body of the message

Reply via email to