Please update your secret keys!

Gary F Mitchell
17-Nov-1999
These notes are available on-line at
newkey.htm

Why it is important

If you don't do it you will not be able to log in properly from Wednesday 01-Dec-1999. The ability to update your secret keys is provided only until MONDAY 29th NOVEMBER 12:00

What you have to do

A simple job which takes 2 minutes.

Open a telnet session to the special host indus (full name indus.roque.ing.iac.es) and log in using your existing password. (If you are unable to log in at all then contact CFG).

When you log in you will almost certainly an error message as in this example:

Connected to indus.roque.ing.iac.es.
Escape character is '^]'.


SunOS 5.7

login: smith
Password: 
Password does not decrypt secret key (type = 192-0) for 'unix.4075@cfg.es'.
Password does not decrypt any secret keys for unix.4075@cfg.es.
smith@indus>

Your number might not be 4075 but the message is the same.

(If you don't see any message then the job has already been done and you can ignore the rest of this note)

To remove this error message this please use "chkey -p" as described below. You will be prompted for two items

Example

smith@indus> chkey -p
Updating nisplus publickey database.
Reencrypting key for 'unix.4075@cfg.es'.
Please enter the Secure-RPC password for smith: casablanca
Please enter the login password for smith: xxxxxx
smith@indus>

Checking it has worked

Log out, wait 1 minute and then log into special host indus again. This time you should see no message about "does not decrypt secret key". Log out. Your keys have now been updated successfully.

If you need assistance

Contact any member of the CFG.

Why is this necessary?

The CFG is reorganizing the way password information in stored. Using just one password you will be able to log in to computers at the Roque and at SLO. If in the future you decide to change your UNIX password you need only change it once on one machine.

Technical Note for those interested...

The CFG is combining the NIS+ domain in use at SLO with the NIS+ domain in use at the Roque into one single NIS+ domain which covers all UNIX sparc computers. While information is preserved it is not technically possible to establish NIS+ credentials for users in the new domain without either re-setting the password or asking the user to use his password to update his secret key. We have chosen the 2nd option and this note is to enable users to do so. The "special host" is the NIS+ master of the new domain. The time limit of 26-Nov-1999 is because users may not normally connect to the NIS+ master. On 01-Dec-1999 all sparcs which are not already in the new NIS+ domain will be switched over.