6840bd89be
Only information leaks now are: * if '-s -s' is used (only allow s/key users, and force s/key use), then "login incorrect" will be given if a non-s/key user (or non-existant user) attempts to login; no password will be prompted for. XXX: maybe this should be fixed, but further analysis is required. * an s/key user will be reminded in the "Password" prompt that they have an s/key. Therefore it would be possible to determine if a user is active on the machine if they have an s/key. XXX: maybe an option is required to control this behaviour |
||
---|---|---|
.. | ||
Makefile | ||
k5login.c | ||
klogin.c | ||
login.1 | ||
login.c | ||
pathnames.h |