
Miscellaneous Procedures 505
OTP Configuration
For more details about OTP, see: http://www.freebsd.org/doc/
en/books/handbook/one-time-passwords.html.
Make sure each user who needs to use OTP
has a local user account, is registered with the
OTP system, and is able to obtain the OTP
username, OTP secret pass phrase, and OTP
passwords needed for logins. See the
following list for options:
“How Users are Registered with OTP and
Obtain OTP Passwords” on page 509
• Register each user yourself and give the
OTP username and OTP secret pass phrase
to each user.
“To Register and Generate OTP Passwords for
Users” on page 510
• Generate the needed OTP passwords on
behalf of the each user and give them to
each user.
• Make sure users are equipped with an OTP
generator that is not on the network to
generate their own OTP passwords when
challenged at login time.
Example:
• User dials into the OnSite through a
PCMCIA modem card that has been
configured to use OTP authentication.
• OnSite challenges with the sequence
number and seed associated with the
username and asks for a response.
• User enters the sequence number, seed,
and the secret pass phrase locally into a
copy of opiekey on the user’s laptop
and obtains an OTP password.
• User answers the OnSite challenge with
the OTP password and gets dial-in
access to the OnSite.
Table 8-1: Tasks for Configuring OTP Authentication (Continued)
Task Where Documented
Comentários a estes Manuais