I have no experience with PAM development, but I'd be willing to commit some time to learning if the following seems reasonably possible: How difficult would it be to implement a pass-through authentication scheme which would allow for existing hardware PAM modules to have the hardware access executed on the remote machine? That is, instead of reading a local USB device, a remote USB device would be read, for those people who are logging in via SSH, X11, etc from a remote system. Other ideas/whack over the head appreciated. - Garrett Kajmowicz _______________________________________________ Pam-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/pam-list