How to let people LOGIN REMOTELY under NetBSD Machines running NetBSD 1.2 are running the correct program (telnetd) to allow remote connections immediately after installation. However, remote connections are restricted to users present in /etc/master.passwd and /etc/passwd. To add someone to thse files, log in as root and run the command: adduser username where "username" has been replaced with the username of the person you are granting remote access. After you have done this, issue the command: cp /etc/master.passwd /etc/master.passwd.local as the file master.passwd is recovered from master.passwd.local each time the machine reboots. IMPORTANT: If you wish to allow for ENCRYPTED connections to your machine,you must request and install a srvtab for the machine. (A srvtab is machine-specific Kerberos keyfile that is necessary for the machine to be able to authenticate incoming network connections) To do this, send mail to accounts@mit.edu stating that you would like a srvtab, and be sure to include the name of the computer the srvtab is to be created for. After one has been created for you, they will send you mail back explaining how to install it. The instructions are as follows: Log in as root on your machine, and issue the command kinit username which will prompt you for your password. Next, do the following: attach tom Then, cd /mit/tom/pickup/FOR_USERNAME/ where "USERNAME" has been replaced with your username (in all caps). There should be a file present in that directory named machinename-new-srvtab where "machinename" is the name of the computer you have requested a srvtab for. Next, cp machinename-new-srvtab /etc/athena/srvtab chown root /etc/athena/srvtab chmod 400 /etc/athena/srvtab ksrvutil change -f /etc/athena/srvtab this last command will change the version number of the srvtab and place the old one in /etc/athena/srvtab.old. You'll probably want to leave this file around until you're sure everything is working correctly, and then you can feel free to delete it. To test if the encryption is working, try logging in as yourself and telnetting to the machine. If encryption is successful, you should see something similar to this: ...including Athena's default telnet options: "-ax" Trying 18.xx.yy.zz... Connected to YOURMACHINE.MIT.EDU. Escape character is '^]'. [ Trying KERBEROS4 ... ] [ Kerberos V4 accepts you ] [ Kerberos V4 challenge successful ] What you type is protected by encryption. Password: If this is the case, then you have set up the srvtab correctly. In that case, you can remove the file /mit/tom/pickup/FOR_USERNAME/machinename-new-srvtab If you are unable to establish an encrypted connection immediately after following these steps, you may need to wait for a period of time to allow the change in version number of the srvtab (the "ksrvutil" command) to propagate. It may also be the case that your own Kerberos tickets might not work with the new version of the key. In that case, you should get new tickets using the "renew" command and see if you are then able to establish an encrypted connection.