1 .\" opiepasswd.1: Manual page for the opiepasswd(1) program.
3 .\" %%% portions-copyright-cmetz-96
4 .\" Portions of this software are Copyright 1996-1999 by Craig Metz, All Rights
5 .\" Reserved. The Inner Net License Version 2 applies to these portions of
7 .\" You should have received a copy of the license with this software. If
8 .\" you didn't get a copy, you may request one from <license@inner.net>.
10 .\" Portions of this software are Copyright 1995 by Randall Atkinson and Dan
11 .\" McDonald, All Rights Reserved. All Rights under this copyright are assigned
12 .\" to the U.S. Naval Research Laboratory (NRL). The NRL Copyright Notice and
13 .\" License Agreement applies to this software.
17 .\" Modified by cmetz for OPIE 2.4. Fixed spelling bug.
18 .\" Modified by cmetz for OPIE 2.3. Added -f flag documentation.
19 .\" Updated console example.
20 .\" Modified by cmetz for OPIE 2.2. Removed MJR DES documentation.
21 .\" Modified at NRL for OPIE 2.0.
22 .\" Written at Bellcore for the S/Key Version 1 software distribution
25 .\" $FreeBSD: head/contrib/opie/opiepasswd.1 92914 2002-03-21 23:42:52Z markm $
29 .TH OPIEPASSWD 1 "January 10, 1995"
32 opiepasswd \- Change or set a user's password for the OPIE authentication
37 [\-v] [\-h] [\-c|\-d] [\-f]
40 .I initial_sequence_number
50 will initialize the system information to allow one to use OPIE to login.
52 is downward compatible with the keyinit(1) program from the
53 Bellcore S/Key Version 1 distribution.
59 Display the version number and compile-time options, then exit.
62 Display a brief help message and exit.
65 Set console mode where the user is expected to have secure access to the
66 system. In console mode, you will be asked to input your password directly
67 instead of having to use an OPIE calculator. If you do not have secure access
68 to the system (i.e., you are not on the system's console), you are
69 volunteering your password to attackers by using this mode.
72 Disable OTP logins to the specified account.
77 to continue, even where it normally shouldn't. This is currently used to
78 force opiepasswd to operate in "console" mode even from terminals it believes
79 to be insecure. It can also allow users to disclose their secret pass phrases
80 to attackers. Use of the -f flag may be disabled by compile-time option in
81 your particular build of OPIE.
84 Manually specify the initial sequence number. The default is 499.
87 Specify a non-random seed. The default is to generate a "random" seed using
88 the first two characters of the host name and five pseudo-random digits.
95 wintermute$ opiepasswd \-c
99 Reminder \- Only use this method from the console; NEVER from remote. If you
101 are using telnet, xterm, or a dial\-in, type ^C now or exit with no password.
103 Then run opiepasswd without the \-c parameter.
105 Using MD5 to compute responses.
107 Enter old secret pass phrase:
109 Enter new secret pass phrase:
111 Again new secret pass phrase:
115 ID kebe OPIE key is 499 be93564
117 CITE JAN GORY BELA GET ABED
126 wintermute$ opiepasswd
130 Reminder: You need the response from your OPIE calculator.
136 Response: FIRM BERN THEE DUCK MANN AWAY
142 Response: SKY FAN BUG HUFF GUS BEAT
146 ID kebe OPIE key is 499 wi93564
148 SKY FAN BUG HUFF GUS BEAT
154 /etc/opiekeys -- database of key information for the OPIE system.
168 Bellcore's S/Key was written by Phil Karn, Neil M. Haller, and John S. Walden
169 of Bellcore. OPIE was created at NRL by Randall Atkinson, Dan McDonald, and
172 S/Key is a trademark of Bell Communications Research (Bellcore).
175 OPIE is discussed on the Bellcore "S/Key Users" mailing list. To join,
176 send an email request to:
178 skey-users-request@thumper.bellcore.com