In this scenario the user would need to generate their own keypair and put it on a USB stick. We could provide tools for that. It should also be possible for local administrators to set policy regarding key importing for the kind of situation you're describing.
no subject