A method, system, and program product for enabling administrative recovery
of a user's lost/forgotten boot-up passwords without compromising the
administrative/master password(s). A restricted-use password is
dynamically generated from a first hash of a random number generated on a
client system and a secret retrieved from a secure device associated with
the client system. The restricted-use password operates as a master
password but is not the administrative password of the client system.
Once the password is generated, it is provided to the user/client system
to enable user access to said client system and hardfile and reset of the
user passwords.