On Fri, Sep 05, 2003 at 12:30:05PM -0600, Dan O'Reilly wrote: > Why not use the methodology used by SSH-KEYGEN? It's simple to implement > and would be in keeping with that used on the server already. the server does not need to see the private key. i also think that the server should _never_ see the private key.