s/key authentication for Apache on FreeBSD?

bruce at nikkel.com bruce at nikkel.com
Wed Dec 10 12:26:27 PST 2003


> What's needed is one-time passwords for "basic" authentication in
> Apache.

The problem with using s/key (or opie) together with http basic auth is
the repetive nature of http requests. The webserver would expect see
the basic authentication string with every single request. You would be
promtped for your next onetime password for every single gif or link on
the page requested. I don't know how practical that would be.

Bruce Nikkel


-- 


More information about the freebsd-security mailing list