<SNIP> > I use pap/chap in a generic sense (username, * for servername, secret, and * > for ip), so I shouldn't technically need the secrets files...but I'm not > sure to what extent PAM is integrated with PPP. well, you can use on /etc/ppp/pap-secrets client server secret ip * $(hostname) "" * and PAM would make the validation as you specified on /etc/pam.d/ppp so you can get your users to use their own login/password for the RAS. HTH Carlo