When creating a cpu/auth kernel, one needs to create a variety of
key/passwords - the machine key, the secstore key, and the hostowner password.

I _think_ I have the basics understood regarding the purpose of these, but one
thing I'm uncertain of:

Aside from the point in which they're each first set, when will they ever be
manually used again?

When I say "when will they be manually used again", I mean... will a user ever
be prompted to enter them again in order to perform some administrative action
or another?

I've yet to actually be prompted for any one of them again after the initial
setup of my cpu/auth server. I imagine at some point I will need to configure
or setup something which will require one of passwords in order to proceed?


Also, what sorts of issues arise if one were to specify non-matching hostowner
passwords, i.e. - when you first boot up after invaliding nvram, you are asked
to specify a hostowner password, then again you are asked to supply a
hostowner password when you run 'auth/changeuser <hostowner>'...

The documentation states that these are supposed to match. But what sorts 
of symptoms will result if you, for instance, typo'd the auth/changeuser
<hostowner> password?


Thanks!


Reply via email to