1 .\" opiepasswd.1: Manual page for the opiepasswd(1) program.
3 .\" %%% portions-copyright-cmetz-96
4 .\" Portions of this software are Copyright 1996-1999 by Craig Metz, All Rights
5 .\" Reserved. The Inner Net License Version 2 applies to these portions of
7 .\" You should have received a copy of the license with this software. If
8 .\" you didn't get a copy, you may request one from <license@inner.net>.
10 .\" Portions of this software are Copyright 1995 by Randall Atkinson and Dan
11 .\" McDonald, All Rights Reserved. All Rights under this copyright are assigned
12 .\" to the U.S. Naval Research Laboratory (NRL). The NRL Copyright Notice and
13 .\" License Agreement applies to this software.
17 .\" Modified by cmetz for OPIE 2.4. Fixed spelling bug.
18 .\" Modified by cmetz for OPIE 2.3. Added -f flag documentation.
19 .\" Updated console example.
20 .\" Modified by cmetz for OPIE 2.2. Removed MJR DES documentation.
21 .\" Modified at NRL for OPIE 2.0.
22 .\" Written at Bellcore for the S/Key Version 1 software distribution
25 .\" $FreeBSD: src/contrib/opie/opiepasswd.1,v 1.3.6.3 2002/07/15 14:48:43 des Exp $
26 .\" $DragonFly: src/contrib/opie/opiepasswd.1,v 1.2 2003/06/17 04:24:05 dillon Exp $
30 .TH OPIEPASSWD 1 "January 10, 1995"
33 opiepasswd \- Change or set a user's password for the OPIE authentication
38 [\-v] [\-h] [\-c|\-d] [\-f]
41 .I initial_sequence_number
51 will initialize the system information to allow one to use OPIE to login.
53 is downward compatible with the keyinit(1) program from the
54 Bellcore S/Key Version 1 distribution.
60 Display the version number and compile-time options, then exit.
63 Display a brief help message and exit.
66 Set console mode where the user is expected to have secure access to the
67 system. In console mode, you will be asked to input your password directly
68 instead of having to use an OPIE calculator. If you do not have secure access
69 to the system (i.e., you are not on the system's console), you are
70 volunteering your password to attackers by using this mode.
73 Disable OTP logins to the specified account.
78 to continue, even where it normally shouldn't. This is currently used to
79 force opiepasswd to operate in "console" mode even from terminals it believes
80 to be insecure. It can also allow users to disclose their secret pass phrases
81 to attackers. Use of the -f flag may be disabled by compile-time option in
82 your particular build of OPIE.
85 Manually specify the initial sequence number. The default is 499.
88 Specify a non-random seed. The default is to generate a "random" seed using
89 the first two characters of the host name and five pseudo-random digits.
96 wintermute$ opiepasswd \-c
100 Reminder \- Only use this method from the console; NEVER from remote. If you
102 are using telnet, xterm, or a dial\-in, type ^C now or exit with no password.
104 Then run opiepasswd without the \-c parameter.
106 Using MD5 to compute responses.
108 Enter old secret pass phrase:
110 Enter new secret pass phrase:
112 Again new secret pass phrase:
116 ID kebe OPIE key is 499 be93564
118 CITE JAN GORY BELA GET ABED
127 wintermute$ opiepasswd
131 Reminder: You need the response from your OPIE calculator.
137 Response: FIRM BERN THEE DUCK MANN AWAY
143 Response: SKY FAN BUG HUFF GUS BEAT
147 ID kebe OPIE key is 499 wi93564
149 SKY FAN BUG HUFF GUS BEAT
155 /etc/opiekeys -- database of key information for the OPIE system.
169 Bellcore's S/Key was written by Phil Karn, Neil M. Haller, and John S. Walden
170 of Bellcore. OPIE was created at NRL by Randall Atkinson, Dan McDonald, and
173 S/Key is a trademark of Bell Communications Research (Bellcore).
176 OPIE is discussed on the Bellcore "S/Key Users" mailing list. To join,
177 send an email request to:
179 skey-users-request@thumper.bellcore.com