1*57718be8SEnji Cooper# $NetBSD: sshd_config.in,v 1.2 2011/02/11 13:19:46 pooka Exp $ 2*57718be8SEnji Cooper 3*57718be8SEnji Cooper# Basic settings. 4*57718be8SEnji CooperPort 10000 5*57718be8SEnji CooperProtocol 2 6*57718be8SEnji Cooper 7*57718be8SEnji Cooper# Provide information to the user in case something goes wrong. 8*57718be8SEnji CooperLogLevel DEBUG1 9*57718be8SEnji Cooper 10*57718be8SEnji Cooper# The host key. It lives in the work directory because we need to set 11*57718be8SEnji Cooper# very strict permissions on it and cannot modify the copy on the source 12*57718be8SEnji Cooper# directory. 13*57718be8SEnji CooperHostKey @WORKDIR@/ssh_host_key 14*57718be8SEnji Cooper 15*57718be8SEnji Cooper# The authorized keys file we set up during the test to allow the client 16*57718be8SEnji Cooper# to safely log in. We need to disable strict modes because ATF_WORKDIR 17*57718be8SEnji Cooper# usually lives in /tmp, which has 1777 permissions and are not liked by 18*57718be8SEnji Cooper# sshd. 19*57718be8SEnji CooperAuthorizedKeysFile @WORKDIR@/authorized_keys 20*57718be8SEnji CooperStrictModes no 21*57718be8SEnji Cooper 22*57718be8SEnji Cooper# Some settings to allow user runs of sshd. 23*57718be8SEnji CooperPidFile @WORKDIR@/sshd.pid 24*57718be8SEnji CooperSubsystem sftp @WORKDIR@/sftp-server 25*57718be8SEnji CooperUsePam no 26*57718be8SEnji CooperUsePrivilegeSeparation no 27*57718be8SEnji Cooper 28*57718be8SEnji Cooper# The root user should also be able to run the tests. 29*57718be8SEnji CooperPermitRootLogin yes 30*57718be8SEnji Cooper 31*57718be8SEnji Cooper# Be restrictive about access to the temporary server. Only allow key-based 32*57718be8SEnji Cooper# authentication. 33*57718be8SEnji CooperChallengeResponseAuthentication no 34*57718be8SEnji CooperGSSAPIAuthentication no 35*57718be8SEnji CooperHostbasedAuthentication no 36*57718be8SEnji CooperKerberosAuthentication no 37*57718be8SEnji CooperMaxAuthTries 1 38*57718be8SEnji CooperMaxStartups 1 39*57718be8SEnji CooperPasswordAuthentication no 40*57718be8SEnji CooperPubkeyAuthentication yes 41