feature request in sshd: require both "pubkey" & "password"

Carson Gaspar carson at taltos.org
Mon Feb 11 05:47:11 EST 2002


--On Saturday, February 09, 2002 1:17 PM -0800 Dan Kaminsky 
<dan at doxpara.com> wrote:

> What security advantage do you perceive through ordered requirements?  AND
> ops generally commute.

If you require a public key first, you protect against password guessing 
attacks - especially if you have failed password account lockouts.

-- 
Carson




More information about the openssh-unix-dev mailing list