why don't you just overwrite the current (new) passwd file with the old one?
doing this will result in a root account without password.
then create client certificates on your computer and store the public key of the certificate in the file ~/.ssh/authorized_keys (on the iliad)
if you do this and iRex does not fiddle with the userhomes you will always have root access with ssh.
|