On 03/11/06, Gonzalo Servat <[EMAIL PROTECTED]> wrote:

> You don't need root access to create a passwordless login (providing the
> admin's haven't explicitly changed the default).

I know, but imagine asking a server admin in a company where there are
lots of policies, bla bla, if I can have a passwordless login on an
account with special sudo privileges :)


I usually think that people who suggest what I'm going to suggest are
unrealistic puristic psychos, but still:
QUIT.

Using private/public keys instead of passwords should enhance security, not
the other way around - if this account can do sudo then it is security's
interest to force it to use keys and forbid use of passwords to login.

If I'd find myself work for a place which can't comprehend this - I'd try to
convince them or move on.

Cheers,

--P
--
SLUG - Sydney Linux User's Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html

Reply via email to