summaryrefslogtreecommitdiffstats
path: root/usr.bin/keyinit/keyinit.1
blob: 31cd25402f3d5c2d8e56c22b16ae52f487a546b6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
.\"	@(#)keyinit.1	1.0 (Bellcore) 7/20/93
.\"
.Dd July 20, 1993
.Dt KEYINIT 1
.Os
.Sh NAME
.Nm keyinit
.Nd change password or add user to S/Key authentication system
.Sh SYNOPSIS
.Nm
.Op Fl s
.Op Ar userID 
.Sh DESCRIPTION
.Nm Keyinit
initializes the system so you can use S/Key one-time passwords to
login.  The program will ask you to enter a secret pass phrase; enter a
phrase of several words in response. After the S/Key database has been
updated you can login using either your regular UNIX password or using
S/Key one-time passwords. 
.Pp
When logging in from another machine you can avoid typing a real
password over the network, by typing your S/Key pass phrase to the
.Nm key
command on the local machine:  the program will respond with
the one-time password that you should use to log into the remote
machine.  This is most conveniently done with cut-and-paste operations
using a mouse.  Alternatively, you can pre-compute one-time passwords
using the
.Nm key
command and carry them with you on a piece of paper.
.Pp
.Nm Keyinit
requires you to type your secret password, so it should
be used only on a secure terminal. For example, on the console of a
workstation. If you are using
.Nm
while logged in over an
untrusted network, follow the instructions given below with the
.Fl s
option.
.Sh OPTIONS
.Bl -tag -width indent
.It Fl s
Set secure mode where the user is expected to have used a secure
machine to generate the first one time password.  Without the
.Fl s
the
system will assume you are direct connected over secure communications
and prompt you for your secret password.
The
.Fl s
option also allows one to set the seed and count for complete
control of the parameters.  You can use
.Nm
.Fl s
in combination with
the 
.Nm key
command to set the seed and count if you do not like the defaults.
To do this run
.Nm
in one window and put in your count and seed
then run
.Nm key
in another window to generate the correct 6 English words
for that count and seed. You can then
"cut" and "paste" them or copy them into the
.Nm
window.
.It Ar userID
The ID for the user to be changed/added
.El
.Sh FILES
.Pa /etc/skeykeys
data base of information for S/Key system.
.Sh SEE ALSO
.Xr key 1 ,
.Xr keyinfo 1 ,
.Xr skey 1 ,
.Xr su 1
.Sh AUTHOR
Command by Phil Karn, Neil M. Haller, John S. Walden
OpenPOWER on IntegriCloud