|
Name |
|
Date |
Size |
#Lines |
LOC |
| .. | | - | - |
| .github/ | H | - | - | 2,101 | 1,798 |
| contrib/ | H | - | - | 5,280 | 3,662 |
| m4/ | H | - | - | 233 | 224 |
| openbsd-compat/ | H | - | - | 21,934 | 14,194 |
| regress/ | H | - | - | 32,546 | 26,440 |
| .depend | H A D | 09-Jul-2026 | 131.6 KiB | 180 | 178 |
| .git_allowed_signers | H A D | 26-Aug-2025 | 1.5 KiB | 12 | 8 |
| .git_allowed_signers.asc | H A D | 09-Jul-2026 | 833 | 17 | 15 |
| .gitignore | H A D | 14-May-2026 | 459 | 40 | 38 |
| .skipped-commit-ids | H A D | 09-Jul-2026 | 4.5 KiB | 78 | 75 |
| CREDITS | H A D | 08-Sep-2021 | 5.4 KiB | 103 | 98 |
| ChangeLog | H A D | 09-Jul-2026 | 360.6 KiB | 11,148 | 7,140 |
| FREEBSD-upgrade | H A D | 24-Aug-2026 | 6.8 KiB | 208 | 135 |
| INSTALL | H A D | 14-May-2026 | 10.2 KiB | 299 | 206 |
| LICENCE | H A D | 19-Feb-2025 | 20.6 KiB | 413 | 366 |
| Makefile.in | H A D | 09-Jul-2026 | 33.9 KiB | 894 | 757 |
| OVERVIEW | H A D | 08-Sep-2021 | 6.2 KiB | 163 | 119 |
| PROTOCOL | H A D | 14-May-2026 | 24.7 KiB | 722 | 524 |
| PROTOCOL.agent | H A D | 09-Jul-2026 | 4 KiB | 108 | 82 |
| PROTOCOL.key | H A D | 19-Feb-2025 | 1.6 KiB | 72 | 53 |
| PROTOCOL.krl | H A D | 11-Aug-2023 | 6.9 KiB | 223 | 154 |
| PROTOCOL.mux | H A D | 18-Mar-2024 | 8.8 KiB | 297 | 218 |
| PROTOCOL.sshsig | H A D | 08-Sep-2021 | 3.3 KiB | 101 | 74 |
| PROTOCOL.u2f | H A D | 08-Sep-2021 | 10.8 KiB | 310 | 243 |
| README | H A D | 09-Jul-2026 | 2 KiB | 50 | 35 |
| README.dns | H A D | 08-Sep-2021 | 1.6 KiB | 48 | 30 |
| README.md | H A D | 14-May-2026 | 5.5 KiB | 90 | 59 |
| README.platform | H A D | 18-Mar-2024 | 4 KiB | 98 | 74 |
| README.privsep | H A D | 09-Jul-2026 | 8 KiB | 174 | 144 |
| README.tun | H A D | 30-Sep-2006 | 4.8 KiB | 133 | 98 |
| SECURITY.md | H A D | 13-Apr-2022 | 163 | 6 | 3 |
| TODO | H A D | 12-May-2026 | 2.5 KiB | 81 | 61 |
| aclocal.m4 | H A D | 06-Feb-2023 | 694 | 16 | 11 |
| addr.c | H A D | 14-May-2026 | 10.1 KiB | 511 | 388 |
| addr.h | H A D | 14-May-2026 | 1.9 KiB | 54 | 32 |
| addrmatch.c | H A D | 14-May-2026 | 4.3 KiB | 167 | 106 |
| atomicio.c | H A D | 12-May-2026 | 4.6 KiB | 174 | 123 |
| atomicio.h | H A D | 08-Sep-2021 | 2.2 KiB | 54 | 14 |
| audit-bsm.c | H A D | 14-May-2026 | 11.7 KiB | 456 | 322 |
| audit-linux.c | H A D | 12-May-2026 | 3.5 KiB | 127 | 79 |
| audit.c | H A D | 08-Sep-2021 | 5.7 KiB | 185 | 105 |
| audit.h | H A D | 08-Sep-2021 | 2.3 KiB | 58 | 28 |
| auth-bsdauth.c | H A D | 14-May-2026 | 3.5 KiB | 136 | 91 |
| auth-krb5.c | H A D | 14-May-2026 | 6.9 KiB | 274 | 201 |
| auth-options.c | H A D | 14-May-2026 | 23.5 KiB | 911 | 748 |
| auth-options.h | H A D | 08-Sep-2021 | 3.1 KiB | 107 | 40 |
| auth-pam.c | H A D | 14-May-2026 | 33.7 KiB | 1,323 | 1,024 |
| auth-pam.h | H A D | 14-May-2026 | 1.9 KiB | 48 | 20 |
| auth-passwd.c | H A D | 12-May-2026 | 6.4 KiB | 224 | 147 |
| auth-rhosts.c | H A D | 12-May-2026 | 9.1 KiB | 336 | 222 |
| auth-shadow.c | H A D | 12-May-2026 | 4.2 KiB | 142 | 86 |
| auth-sia.c | H A D | 11-Sep-2018 | 3.2 KiB | 116 | 71 |
| auth-sia.h | H A D | 05-Jun-2005 | 1.4 KiB | 32 | 4 |
| auth.c | H A D | 14-May-2026 | 21.6 KiB | 792 | 630 |
| auth.h | H A D | 09-Jul-2026 | 8.1 KiB | 248 | 156 |
| auth2-chall.c | H A D | 09-Jul-2026 | 9.5 KiB | 369 | 292 |
| auth2-gss.c | H A D | 09-Jul-2026 | 9.5 KiB | 334 | 242 |
| auth2-hostbased.c | H A D | 14-May-2026 | 8.3 KiB | 269 | 212 |
| auth2-kbdint.c | H A D | 19-Feb-2025 | 2.2 KiB | 72 | 35 |
| auth2-methods.c | H A D | 19-Feb-2025 | 3.3 KiB | 135 | 97 |
| auth2-none.c | H A D | 14-May-2026 | 2.1 KiB | 70 | 36 |
| auth2-passwd.c | H A D | 19-Feb-2025 | 2.4 KiB | 80 | 45 |
| auth2-pubkey.c | H A D | 14-May-2026 | 25.3 KiB | 880 | 725 |
| auth2-pubkeyfile.c | H A D | 14-May-2026 | 14.2 KiB | 514 | 375 |
| auth2.c | H A D | 09-Jul-2026 | 22.1 KiB | 815 | 629 |
| authfd.c | H A D | 09-Jul-2026 | 20.8 KiB | 827 | 630 |
| authfd.h | H A D | 14-May-2026 | 4.2 KiB | 125 | 80 |
| authfile.c | H A D | 09-Jul-2026 | 12.3 KiB | 522 | 390 |
| authfile.h | H A D | 08-Sep-2021 | 2.4 KiB | 55 | 22 |
| bitmap.c | H A D | 11-May-2018 | 4.4 KiB | 215 | 171 |
| bitmap.h | H A D | 11-May-2018 | 1.9 KiB | 58 | 15 |
| blocklist.c | H A D | 12-Oct-2025 | 2.8 KiB | 98 | 50 |
| blocklist_client.h | H A D | 12-Oct-2025 | 2.1 KiB | 62 | 20 |
| buildpkg.sh.in | H A D | 26-Aug-2025 | 17.6 KiB | 678 | 526 |
| canohost.c | H A D | 14-May-2026 | 4.7 KiB | 209 | 146 |
| canohost.h | H A D | 02-Mar-2017 | 842 | 27 | 9 |
| chacha.c | H A D | 09-Jul-2026 | 5.3 KiB | 219 | 188 |
| chacha.h | H A D | 08-Sep-2021 | 994 | 37 | 22 |
| channels.c | H A D | 09-Jul-2026 | 149.6 KiB | 5,451 | 4,300 |
| channels.h | H A D | 09-Jul-2026 | 15.7 KiB | 418 | 272 |
| cipher-aes.c | H A D | 11-Aug-2023 | 4.5 KiB | 162 | 119 |
| cipher-aesctr.c | H A D | 14-May-2026 | 2.1 KiB | 84 | 50 |
| cipher-aesctr.h | H A D | 22-Jan-2016 | 1.3 KiB | 36 | 13 |
| cipher-chachapoly-libcrypto.c | H A D | 14-May-2026 | 4.9 KiB | 164 | 111 |
| cipher-chachapoly.c | H A D | 11-Aug-2023 | 4.1 KiB | 139 | 86 |
| cipher-chachapoly.h | H A D | 08-Sep-2021 | 1.6 KiB | 41 | 17 |
| cipher.c | H A D | 09-Jul-2026 | 12.1 KiB | 474 | 377 |
| cipher.h | H A D | 09-Jul-2026 | 3.1 KiB | 78 | 34 |
| cleanup.c | H A D | 30-Sep-2006 | 1 KiB | 33 | 10 |
| clientloop.c | H A D | 09-Jul-2026 | 83.6 KiB | 2,894 | 2,129 |
| clientloop.h | H A D | 14-May-2026 | 3.8 KiB | 86 | 33 |
| compat.c | H A D | 14-May-2026 | 5.1 KiB | 167 | 130 |
| compat.h | H A D | 16-Mar-2023 | 2.5 KiB | 66 | 22 |
| config.guess | H A D | 06-Feb-2023 | 48.8 KiB | 1,775 | 1,548 |
| config.h | H A D | 09-Jul-2026 | 58.5 KiB | 2,129 | 396 |
| config.sub | H A D | 06-Feb-2023 | 35 KiB | 1,908 | 1,720 |
| configure.ac | H A D | 09-Jul-2026 | 163.4 KiB | 6,056 | 5,689 |
| crypto_api.h | H A D | 09-Jul-2026 | 7.9 KiB | 211 | 170 |
| defines.h | H A D | 09-Jul-2026 | 25.9 KiB | 1,011 | 769 |
| dh.c | H A D | 14-May-2026 | 15.4 KiB | 505 | 403 |
| dh.h | H A D | 08-Sep-2021 | 2.7 KiB | 85 | 36 |
| digest-libc.c | H A D | 14-May-2026 | 6.1 KiB | 268 | 216 |
| digest-openssl.c | H A D | 08-Sep-2021 | 4.9 KiB | 208 | 160 |
| digest.h | H A D | 09-May-2018 | 2.5 KiB | 71 | 32 |
| dispatch.c | H A D | 14-May-2026 | 3.5 KiB | 135 | 95 |
| dispatch.h | H A D | 14-May-2026 | 2 KiB | 50 | 17 |
| dns.c | H A D | 14-May-2026 | 8.7 KiB | 338 | 239 |
| dns.h | H A D | 12-May-2026 | 2 KiB | 59 | 25 |
| ed25519-openssl.c | H A D | 09-Jul-2026 | 6.3 KiB | 244 | 178 |
| ed25519.c | H A D | 09-Jul-2026 | 197.7 KiB | 2,065 | 1,783 |
| ed25519.sh | H A D | 09-Jul-2026 | 5.8 KiB | 184 | 145 |
| entropy.c | H A D | 14-May-2026 | 3.5 KiB | 132 | 73 |
| entropy.h | H A D | 14-May-2026 | 1.4 KiB | 34 | 6 |
| fatal.c | H A D | 08-Sep-2021 | 1.8 KiB | 47 | 14 |
| fixalgorithms | H A D | 30-Oct-2013 | 422 | 27 | 13 |
| fixpaths | H A D | 23-Apr-2003 | 499 | 23 | 12 |
| freebsd-configure.sh | H A D | 17-May-2026 | 1.9 KiB | 65 | 38 |
| freebsd-namespace.sh | H A D | 23-Apr-2022 | 1.9 KiB | 84 | 56 |
| groupaccess.c | H A D | 12-May-2026 | 3.8 KiB | 146 | 90 |
| groupaccess.h | H A D | 01-Aug-2008 | 1.5 KiB | 36 | 7 |
| gss-genr.c | H A D | 14-May-2026 | 7.9 KiB | 304 | 210 |
| gss-serv-krb5.c | H A D | 14-May-2026 | 5.6 KiB | 212 | 143 |
| gss-serv.c | H A D | 14-May-2026 | 10.5 KiB | 412 | 262 |
| hmac.c | H A D | 14-May-2026 | 5.1 KiB | 198 | 149 |
| hmac.h | H A D | 22-Jan-2016 | 1.6 KiB | 39 | 15 |
| hostfile.c | H A D | 14-May-2026 | 25.7 KiB | 983 | 767 |
| hostfile.h | H A D | 08-Sep-2021 | 4.4 KiB | 124 | 75 |
| includes.h | H A D | 26-Aug-2025 | 3.9 KiB | 185 | 141 |
| install-sh | H A D | 06-Feb-2023 | 15 KiB | 542 | 352 |
| kex-names.c | H A D | 14-May-2026 | 8.5 KiB | 337 | 251 |
| kex.c | H A D | 09-Jul-2026 | 38.3 KiB | 1,449 | 1,229 |
| kex.h | H A D | 09-Jul-2026 | 9.8 KiB | 297 | 237 |
| kexc25519.c | H A D | 19-Feb-2025 | 5.8 KiB | 200 | 149 |
| kexdh.c | H A D | 14-May-2026 | 5 KiB | 202 | 159 |
| kexecdh.c | H A D | 14-May-2026 | 6.1 KiB | 239 | 187 |
| kexgen.c | H A D | 14-May-2026 | 10.9 KiB | 385 | 317 |
| kexgex.c | H A D | 14-May-2026 | 3.7 KiB | 105 | 70 |
| kexgexc.c | H A D | 14-May-2026 | 7 KiB | 241 | 186 |
| kexgexs.c | H A D | 14-May-2026 | 6.4 KiB | 216 | 159 |
| kexmlkem768x25519.c | H A D | 09-Jul-2026 | 7.8 KiB | 262 | 208 |
| kexsntrup761x25519.c | H A D | 19-Feb-2025 | 7.7 KiB | 256 | 202 |
| krb5_config.h | H A D | 14-May-2026 | 658 | 20 | 19 |
| krl.c | H A D | 14-May-2026 | 35.6 KiB | 1,389 | 1,159 |
| krl.h | H A D | 14-May-2026 | 2.7 KiB | 68 | 38 |
| libcrux-mlkem-mldsa.c | H A D | 09-Jul-2026 | 12.7 KiB | 431 | 348 |
| libcrux_internal.h | H A D | 09-Jul-2026 | 835.2 KiB | 27,333 | 18,201 |
| log.c | H A D | 14-May-2026 | 16.7 KiB | 657 | 507 |
| log.h | H A D | 26-Aug-2025 | 7.1 KiB | 150 | 113 |
| loginrec.c | H A D | 14-May-2026 | 41.7 KiB | 1,759 | 1,148 |
| loginrec.h | H A D | 14-May-2026 | 4.7 KiB | 139 | 57 |
| logintest.c | H A D | 12-May-2026 | 8.5 KiB | 307 | 212 |
| mac.c | H A D | 09-Jul-2026 | 7 KiB | 256 | 201 |
| mac.h | H A D | 14-May-2026 | 2 KiB | 54 | 24 |
| match.c | H A D | 09-Jul-2026 | 10.7 KiB | 407 | 229 |
| match.h | H A D | 08-Sep-2021 | 1.2 KiB | 31 | 14 |
| mdoc2man.awk | H A D | 14-May-2026 | 8.5 KiB | 379 | 349 |
| misc-agent.c | H A D | 14-May-2026 | 8.9 KiB | 358 | 288 |
| misc.c | H A D | 09-Jul-2026 | 69.3 KiB | 3,230 | 2,520 |
| misc.h | H A D | 14-May-2026 | 9.8 KiB | 280 | 209 |
| mkinstalldirs | H A D | 11-May-2018 | 633 | 39 | 23 |
| mlkem_mldsa.sh | H A D | 09-Jul-2026 | 10.5 KiB | 342 | 296 |
| moduli | H A D | 09-Jul-2026 | 658.1 KiB | 541 | 540 |
| moduli.5 | H A D | 19-Oct-2022 | 3.6 KiB | 127 | 126 |
| moduli.c | H A D | 14-May-2026 | 19.3 KiB | 772 | 479 |
| monitor.c | H A D | 09-Jul-2026 | 55.4 KiB | 2,093 | 1,653 |
| monitor.h | H A D | 14-May-2026 | 4.2 KiB | 107 | 63 |
| monitor_fdpass.c | H A D | 14-May-2026 | 4.5 KiB | 177 | 136 |
| monitor_fdpass.h | H A D | 01-Aug-2008 | 1.5 KiB | 35 | 5 |
| monitor_wrap.c | H A D | 09-Jul-2026 | 29.9 KiB | 1,200 | 954 |
| monitor_wrap.h | H A D | 09-Jul-2026 | 4.3 KiB | 115 | 69 |
| msg.c | H A D | 14-May-2026 | 2.7 KiB | 93 | 58 |
| msg.h | H A D | 22-Jan-2016 | 1.5 KiB | 33 | 6 |
| mux.c | H A D | 14-May-2026 | 66.1 KiB | 2,490 | 2,076 |
| myproposal.h | H A D | 14-May-2026 | 3.9 KiB | 122 | 84 |
| nchan.c | H A D | 14-May-2026 | 11.9 KiB | 444 | 343 |
| nchan.ms | H A D | 30-Oct-2013 | 3.9 KiB | 100 | 74 |
| nchan2.ms | H A D | 30-Oct-2013 | 3.4 KiB | 89 | 64 |
| openssh.xml.in | H A D | 30-Oct-2013 | 2.8 KiB | 91 | 61 |
| opensshd.init.in | H A D | 19-Dec-2021 | 1.2 KiB | 69 | 46 |
| packet.c | H A D | 09-Jul-2026 | 83.1 KiB | 3,132 | 2,414 |
| packet.h | H A D | 14-May-2026 | 7.6 KiB | 229 | 164 |
| pathnames.h | H A D | 09-Jul-2026 | 6.3 KiB | 192 | 79 |
| pkcs11.h | H A D | 12-May-2026 | 60.8 KiB | 1,902 | 1,616 |
| platform-listen.c | H A D | 26-Aug-2025 | 2.2 KiB | 102 | 66 |
| platform-misc.c | H A D | 09-May-2018 | 1.1 KiB | 36 | 13 |
| platform-pledge.c | H A D | 14-Mar-2016 | 1.9 KiB | 72 | 27 |
| platform-tracing.c | H A D | 09-Nov-2022 | 2.5 KiB | 77 | 47 |
| platform.c | H A D | 12-May-2026 | 5.3 KiB | 215 | 143 |
| platform.h | H A D | 26-Aug-2025 | 1.5 KiB | 41 | 20 |
| poly1305.c | H A D | 12-May-2026 | 4.5 KiB | 158 | 119 |
| poly1305.h | H A D | 22-Jan-2016 | 645 | 23 | 11 |
| progressmeter.c | H A D | 14-May-2026 | 7.5 KiB | 304 | 219 |
| progressmeter.h | H A D | 08-Sep-2021 | 1.5 KiB | 29 | 3 |
| readconf.c | H A D | 09-Jul-2026 | 111.4 KiB | 3,958 | 3,361 |
| readconf.h | H A D | 14-May-2026 | 9.2 KiB | 265 | 196 |
| readpass.c | H A D | 14-May-2026 | 8.3 KiB | 331 | 254 |
| rijndael.c | H A D | 14-May-2026 | 51.6 KiB | 1,130 | 1,009 |
| rijndael.h | H A D | 13-Apr-2022 | 2 KiB | 56 | 20 |
| sandbox-capsicum.c | H A D | 12-May-2026 | 3 KiB | 111 | 72 |
| sandbox-darwin.c | H A D | 12-May-2026 | 2.2 KiB | 85 | 46 |
| sandbox-null.c | H A D | 26-Aug-2025 | 1.4 KiB | 61 | 27 |
| sandbox-rlimit.c | H A D | 26-Aug-2025 | 2.1 KiB | 82 | 47 |
| sandbox-seccomp-filter.c | H A D | 09-Jul-2026 | 16.9 KiB | 568 | 470 |
| sandbox-solaris.c | H A D | 26-Aug-2025 | 2.7 KiB | 101 | 66 |
| scp.1 | H A D | 12-May-2026 | 8.8 KiB | 368 | 367 |
| scp.c | H A D | 09-Jul-2026 | 53.8 KiB | 2,278 | 1,858 |
| servconf.c | H A D | 10-Jul-2026 | 120.6 KiB | 4,407 | 3,829 |
| servconf.h | H A D | 28-Jul-2026 | 21.9 KiB | 455 | 331 |
| serverloop.c | H A D | 09-Jul-2026 | 28.4 KiB | 923 | 707 |
| serverloop.h | H A D | 09-May-2018 | 1,000 | 29 | 5 |
| session.c | H A D | 09-Jul-2026 | 66.9 KiB | 2,706 | 2,003 |
| session.h | H A D | 06-Feb-2023 | 2.6 KiB | 85 | 48 |
| sftp-client.c | H A D | 09-Jul-2026 | 79 KiB | 3,014 | 2,445 |
| sftp-client.h | H A D | 14-May-2026 | 6.5 KiB | 203 | 79 |
| sftp-common.c | H A D | 14-May-2026 | 6.9 KiB | 264 | 210 |
| sftp-common.h | H A D | 14-May-2026 | 2.1 KiB | 54 | 20 |
| sftp-glob.c | H A D | 14-May-2026 | 4.3 KiB | 180 | 111 |
| sftp-realpath.c | H A D | 19-Dec-2021 | 6 KiB | 226 | 147 |
| sftp-server-main.c | H A D | 19-Oct-2022 | 1.4 KiB | 53 | 27 |
| sftp-server.8 | H A D | 09-Jul-2026 | 5.2 KiB | 182 | 181 |
| sftp-server.c | H A D | 09-Jul-2026 | 52.5 KiB | 2,128 | 1,814 |
| sftp-usergroup.c | H A D | 14-May-2026 | 5.5 KiB | 241 | 188 |
| sftp-usergroup.h | H A D | 19-Oct-2022 | 1.1 KiB | 26 | 4 |
| sftp.1 | H A D | 26-Aug-2025 | 17.6 KiB | 768 | 767 |
| sftp.c | H A D | 09-Jul-2026 | 64.7 KiB | 2,727 | 2,248 |
| sftp.h | H A D | 01-Aug-2008 | 3.3 KiB | 102 | 55 |
| sk-api.h | H A D | 12-May-2026 | 2.8 KiB | 102 | 63 |
| sk-usbhid.c | H A D | 09-Jul-2026 | 38.4 KiB | 1,485 | 1,324 |
| sk_config.h | H A D | 19-Oct-2022 | 338 | 10 | 9 |
| smult_curve25519_ref.c | H A D | 03-Jun-2014 | 6.7 KiB | 266 | 227 |
| sntrup761.c | H A D | 14-May-2026 | 77.9 KiB | 2,152 | 1,952 |
| sntrup761.sh | H A D | 14-May-2026 | 4.4 KiB | 127 | 102 |
| srclimit.c | H A D | 14-May-2026 | 15 KiB | 503 | 422 |
| srclimit.h | H A D | 14-May-2026 | 1.7 KiB | 43 | 21 |
| ssh-add.1 | H A D | 14-May-2026 | 10.9 KiB | 361 | 360 |
| ssh-add.c | H A D | 09-Jul-2026 | 27.2 KiB | 1,065 | 906 |
| ssh-agent.1 | H A D | 09-Jul-2026 | 9.7 KiB | 339 | 338 |
| ssh-agent.c | H A D | 09-Jul-2026 | 70.5 KiB | 2,673 | 2,249 |
| ssh-ecdsa-sk.c | H A D | 14-May-2026 | 14.5 KiB | 507 | 402 |
| ssh-ecdsa.c | H A D | 14-May-2026 | 14.3 KiB | 586 | 489 |
| ssh-ed25519-sk.c | H A D | 14-May-2026 | 7.5 KiB | 287 | 237 |
| ssh-ed25519.c | H A D | 14-May-2026 | 8.2 KiB | 336 | 278 |
| ssh-gss.h | H A D | 19-Feb-2025 | 4.7 KiB | 139 | 91 |
| ssh-keygen.1 | H A D | 09-Jul-2026 | 41.2 KiB | 1,357 | 1,356 |
| ssh-keygen.c | H A D | 09-Jul-2026 | 105.9 KiB | 3,938 | 3,435 |
| ssh-keyscan.1 | H A D | 09-Jul-2026 | 5.1 KiB | 198 | 197 |
| ssh-keyscan.c | H A D | 09-Jul-2026 | 19 KiB | 837 | 696 |
| ssh-keysign.8 | H A D | 19-Feb-2025 | 2.9 KiB | 92 | 91 |
| ssh-keysign.c | H A D | 09-Jul-2026 | 8.1 KiB | 309 | 230 |
| ssh-mldsa-eddsa.c | H A D | 09-Jul-2026 | 13.1 KiB | 507 | 412 |
| ssh-pkcs11-client.c | H A D | 14-May-2026 | 12.1 KiB | 494 | 399 |
| ssh-pkcs11-helper.8 | H A D | 19-Oct-2022 | 1.7 KiB | 72 | 71 |
| ssh-pkcs11-helper.c | H A D | 14-May-2026 | 8 KiB | 325 | 256 |
| ssh-pkcs11.c | H A D | 14-May-2026 | 59.1 KiB | 2,330 | 1,913 |
| ssh-pkcs11.h | H A D | 14-May-2026 | 1.8 KiB | 50 | 24 |
| ssh-rsa.c | H A D | 14-May-2026 | 16.4 KiB | 668 | 563 |
| ssh-sandbox.h | H A D | 26-Aug-2025 | 996 | 23 | 4 |
| ssh-sk-client.c | H A D | 14-May-2026 | 11.8 KiB | 501 | 427 |
| ssh-sk-helper.8 | H A D | 19-Oct-2022 | 1.7 KiB | 72 | 71 |
| ssh-sk-helper.c | H A D | 14-May-2026 | 10.3 KiB | 384 | 301 |
| ssh-sk.c | H A D | 12-May-2026 | 22.8 KiB | 893 | 780 |
| ssh-sk.h | H A D | 13-Apr-2022 | 2.7 KiB | 80 | 27 |
| ssh.1 | H A D | 25-Aug-2026 | 46.6 KiB | 1,806 | 1,805 |
| ssh.c | H A D | 09-Jul-2026 | 73.7 KiB | 2,505 | 1,956 |
| ssh.h | H A D | 26-Aug-2025 | 2.5 KiB | 94 | 18 |
| ssh2.h | H A D | 05-Jan-2024 | 5.8 KiB | 181 | 81 |
| ssh_api.c | H A D | 14-May-2026 | 15.2 KiB | 593 | 472 |
| ssh_api.h | H A D | 14-May-2026 | 4.3 KiB | 137 | 31 |
| ssh_config | H A D | 12-May-2026 | 1.5 KiB | 46 | 41 |
| ssh_config.5 | H A D | 09-Jul-2026 | 70.3 KiB | 2,488 | 2,487 |
| ssh_namespace.h | H A D | 09-Jul-2026 | 57.5 KiB | 1,089 | 1,084 |
| sshbuf-getput-basic.c | H A D | 14-May-2026 | 13 KiB | 670 | 559 |
| sshbuf-getput-crypto.c | H A D | 14-May-2026 | 4.6 KiB | 191 | 149 |
| sshbuf-io.c | H A D | 09-Jul-2026 | 2.7 KiB | 117 | 85 |
| sshbuf-misc.c | H A D | 14-May-2026 | 8 KiB | 360 | 305 |
| sshbuf.c | H A D | 14-May-2026 | 10.4 KiB | 448 | 352 |
| sshbuf.h | H A D | 09-Jul-2026 | 14.9 KiB | 432 | 179 |
| sshconnect.c | H A D | 09-Jul-2026 | 51.8 KiB | 1,817 | 1,419 |
| sshconnect.h | H A D | 09-Jul-2026 | 3.5 KiB | 107 | 62 |
| sshconnect2.c | H A D | 09-Jul-2026 | 65.6 KiB | 2,382 | 1,921 |
| sshd-auth.c | H A D | 09-Jul-2026 | 21.2 KiB | 845 | 615 |
| sshd-debug.sh | H A D | 26-Aug-2025 | 1.4 KiB | 53 | 31 |
| sshd-session.c | H A D | 09-Jul-2026 | 38 KiB | 1,382 | 972 |
| sshd.8 | H A D | 25-Aug-2026 | 32.2 KiB | 1,054 | 1,053 |
| sshd.c | H A D | 09-Jul-2026 | 54.8 KiB | 2,003 | 1,489 |
| sshd_config | H A D | 09-Jul-2026 | 3.5 KiB | 125 | 100 |
| sshd_config.5 | H A D | 09-Jul-2026 | 65.8 KiB | 2,327 | 2,326 |
| ssherr-libcrypto.c | H A D | 09-Jul-2026 | 1.7 KiB | 60 | 36 |
| ssherr-nolibcrypto.c | H A D | 14-May-2026 | 946 | 27 | 7 |
| ssherr.c | H A D | 09-Jul-2026 | 5.3 KiB | 157 | 137 |
| ssherr.h | H A D | 09-Jul-2026 | 3.5 KiB | 94 | 68 |
| sshkey.c | H A D | 09-Jul-2026 | 90.8 KiB | 3,713 | 3,088 |
| sshkey.h | H A D | 09-Jul-2026 | 12.2 KiB | 350 | 265 |
| sshlogin.c | H A D | 14-May-2026 | 5.3 KiB | 174 | 99 |
| sshlogin.h | H A D | 30-Oct-2013 | 935 | 24 | 8 |
| sshpty.c | H A D | 14-May-2026 | 5.6 KiB | 229 | 161 |
| sshpty.h | H A D | 06-Mar-2017 | 1 KiB | 29 | 10 |
| sshsig.c | H A D | 14-May-2026 | 29.5 KiB | 1,165 | 1,008 |
| sshsig.h | H A D | 13-Apr-2022 | 4 KiB | 112 | 36 |
| sshtty.c | H A D | 28-Apr-2010 | 2.9 KiB | 97 | 52 |
| survey.sh.in | H A D | 30-Oct-2013 | 1.7 KiB | 70 | 49 |
| ttymodes.c | H A D | 14-May-2026 | 9.7 KiB | 450 | 327 |
| ttymodes.h | H A D | 09-May-2018 | 4.9 KiB | 170 | 104 |
| uidswap.c | H A D | 14-May-2026 | 7.2 KiB | 238 | 158 |
| uidswap.h | H A D | 11-Sep-2018 | 680 | 18 | 3 |
| umac.c | H A D | 14-May-2026 | 45 KiB | 1,286 | 771 |
| umac.h | H A D | 13-Apr-2022 | 4.6 KiB | 130 | 42 |
| umac128.c | H A D | 23-Apr-2022 | 398 | 18 | 12 |
| utf8.c | H A D | 08-Sep-2021 | 8.2 KiB | 356 | 240 |
| utf8.h | H A D | 08-Sep-2021 | 1.3 KiB | 29 | 11 |
| version.h | H A D | 09-Jul-2026 | 220 | 9 | 4 |
| xmalloc.c | H A D | 12-May-2026 | 2.4 KiB | 117 | 84 |
| xmalloc.h | H A D | 08-Sep-2021 | 1.1 KiB | 28 | 9 |
README
1See https://www.openssh.com/releasenotes.html for the release
2notes.
3
4Please read https://www.openssh.com/report.html for bug reporting
5instructions and note that we do not use Github for bug reporting.
6
7This is the port of OpenBSD's excellent OpenSSH[0] to Linux and other
8Unices.
9
10OpenSSH is based on the last free version of Tatu Ylonen's sample
11implementation with all patent-encumbered algorithms removed (to external
12libraries), all known security bugs fixed, new features reintroduced and
13many other clean-ups. OpenSSH was created by Aaron Campbell, Bob Beck,
14Markus Friedl, Niels Provos, Theo de Raadt, and Dug Song, and has been
15developed and maintained by Andre Lucas, Ben Lindstom, Damien Miller,
16Darren Tucker and Tim Rice. It has a homepage at https://www.openssh.com/
17
18This port consists of the re-introduction of autoconf support, PAM
19support, EGD/PRNGD support and replacements for OpenBSD library
20functions that are (regrettably) absent from other unices. This port
21has been best tested on AIX, Cygwin, HP-UX, Linux, MacOS/X,
22FreeBSD, NetBSD, OpenBSD, OpenServer, Solaris and UnixWare.
23
24This version actively tracks changes in the OpenBSD CVS repository.
25
26There is now several mailing lists for this port of OpenSSH. Please
27refer to https://www.openssh.com/list.html for details on how to join.
28
29Please send bug reports and patches to https://bugzilla.mindrot.org or
30the mailing list openssh-unix-dev@mindrot.org. To mitigate spam, the
31list only allows posting from subscribed addresses. Code contribution
32are welcomed, but please follow the OpenBSD style guidelines[1].
33
34Please refer to the INSTALL document for information on dependencies and
35how to install OpenSSH on your system.
36
37Damien Miller <djm@mindrot.org>
38
39Miscellania -
40
41This version of OpenSSH is based upon code retrieved from the OpenBSD CVS
42repository which in turn was based on the last free sample implementation
43released by Tatu Ylonen.
44
45References -
46
47[0] https://www.openssh.com/
48[1] https://man.openbsd.org/style.9
49
50
README.dns
1How to verify host keys using OpenSSH and DNS
2---------------------------------------------
3
4OpenSSH contains support for verifying host keys using DNS as described
5in https://tools.ietf.org/html/rfc4255. The document contains very brief
6instructions on how to use this feature. Configuring DNS is out of the
7scope of this document.
8
9
10(1) Server: Generate and publish the DNS RR
11
12To create a DNS resource record (RR) containing a fingerprint of the
13public host key, use the following command:
14
15 ssh-keygen -r hostname -f keyfile -g
16
17where "hostname" is your fully qualified hostname and "keyfile" is the
18file containing the public host key file. If you have multiple keys,
19you should generate one RR for each key.
20
21In the example above, ssh-keygen will print the fingerprint in a
22generic DNS RR format parsable by most modern name server
23implementations. If your nameserver has support for the SSHFP RR
24you can omit the -g flag and ssh-keygen will print a standard SSHFP RR.
25
26To publish the fingerprint using the DNS you must add the generated RR
27to your DNS zone file and sign your zone.
28
29
30(2) Client: Enable ssh to verify host keys using DNS
31
32To enable the ssh client to verify host keys using DNS, you have to
33add the following option to the ssh configuration file
34($HOME/.ssh/config or /etc/ssh/ssh_config):
35
36 VerifyHostKeyDNS yes
37
38Upon connection the client will try to look up the fingerprint RR
39using DNS. If the fingerprint received from the DNS server matches
40the remote host key, the user will be notified.
41
42
43 Jakob Schlyter
44 Wesley Griffin
45
46
47$OpenBSD: README.dns,v 1.2 2003/10/14 19:43:23 jakob Exp $
48
README.md
1# Portable OpenSSH
2
3[](../../actions/workflows/c-cpp.yml)
4[](../../actions/workflows/vm.yml)
5[](https://github.com/openssh/openssh-portable-selfhosted/actions/workflows/selfhosted.yml)
6[](../../actions/workflows/cifuzz.yml)
7[](https://issues.oss-fuzz.com/issues?q="Project:+openssh"+is:open)
8[](https://scan.coverity.com/projects/openssh-portable)
9
10OpenSSH is a complete implementation of the SSH protocol (version 2) for secure remote login, command execution and file transfer. It includes a client ``ssh`` and server ``sshd``, file transfer utilities ``scp`` and ``sftp`` as well as tools for key generation (``ssh-keygen``), run-time key storage (``ssh-agent``) and a number of supporting programs.
11
12This is a port of OpenBSD's [OpenSSH](https://openssh.com) to most Unix-like operating systems, including Linux, OS X and Cygwin. Portable OpenSSH polyfills OpenBSD APIs that are not available elsewhere, adds sshd sandboxing for more operating systems and includes support for OS-native authentication and auditing (e.g. using PAM).
13
14## Documentation
15
16The official documentation for OpenSSH are the man pages for each tool:
17
18* [ssh(1)](https://man.openbsd.org/ssh.1)
19* [sshd(8)](https://man.openbsd.org/sshd.8)
20* [ssh-keygen(1)](https://man.openbsd.org/ssh-keygen.1)
21* [ssh-agent(1)](https://man.openbsd.org/ssh-agent.1)
22* [scp(1)](https://man.openbsd.org/scp.1)
23* [sftp(1)](https://man.openbsd.org/sftp.1)
24* [ssh-keyscan(8)](https://man.openbsd.org/ssh-keyscan.8)
25* [sftp-server(8)](https://man.openbsd.org/sftp-server.8)
26
27## Stable Releases
28
29Stable release tarballs are available from a number of [download mirrors](https://www.openssh.com/portable.html#downloads). We recommend the use of a stable release for most users. Please read the [release notes](https://www.openssh.com/releasenotes.html) for details of recent changes and potential incompatibilities.
30
31## Building Portable OpenSSH
32
33### Dependencies
34
35Portable OpenSSH is built using autoconf and make. It requires a working C compiler, standard library and headers.
36
37``libcrypto`` from one of [LibreSSL](https://www.libressl.org/), [OpenSSL](https://www.openssl.org), [AWS-LC](https://github.com/aws/aws-lc) or [BoringSSL](https://github.com/google/boringssl) may also be used. OpenSSH may be built without either of these, but the resulting binaries will have only a subset of the cryptographic algorithms normally available.
38
39[zlib](https://www.zlib.net/) is optional; without it transport compression is not supported.
40
41FIDO security token support needs [libfido2](https://github.com/Yubico/libfido2) and its dependencies and will be enabled automatically if they are found.
42
43In addition, certain platforms and build-time options may require additional dependencies; see README.platform for details about your platform.
44
45### Building a release
46
47Release tarballs and release branches in git include a pre-built copy of the ``configure`` script and may be built using:
48
49```
50tar zxvf openssh-X.YpZ.tar.gz
51cd openssh
52./configure # [options]
53make && make tests
54```
55
56See the [Build-time Customisation](#build-time-customisation) section below for configure options. If you plan on installing OpenSSH to your system, then you will usually want to specify destination paths.
57
58### Building from git
59
60If building from the git master branch, you'll need [autoconf](https://www.gnu.org/software/autoconf/) installed to build the ``configure`` script. The following commands will check out and build portable OpenSSH from git:
61
62```
63git clone https://github.com/openssh/openssh-portable # or https://anongit.mindrot.org/openssh.git
64cd openssh-portable
65autoreconf
66./configure
67make && make tests
68```
69
70### Build-time Customisation
71
72There are many build-time customisation options available. All Autoconf destination path flags (e.g. ``--prefix``) are supported (and are usually required if you want to install OpenSSH).
73
74For a full list of available flags, run ``./configure --help`` but a few of the more frequently-used ones are described below. Some of these flags will require additional libraries and/or headers be installed.
75
76Flag | Meaning
77--- | ---
78``--with-pam`` | Enable [PAM](https://en.wikipedia.org/wiki/Pluggable_authentication_module) support. [OpenPAM](https://www.openpam.org/), [Linux PAM](http://www.linux-pam.org/) and Solaris PAM are supported.
79``--with-libedit`` | Enable [libedit](https://www.thrysoee.dk/editline/) support for sftp.
80``--with-kerberos5`` | Enable Kerberos/GSSAPI support. Both [Heimdal](https://www.h5l.org/) and [MIT](https://web.mit.edu/kerberos/) Kerberos implementations are supported.
81``--with-selinux`` | Enable [SELinux](https://en.wikipedia.org/wiki/Security-Enhanced_Linux) support.
82
83## Development
84
85Portable OpenSSH development is discussed on the [openssh-unix-dev mailing list](https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev) ([archive mirror](https://marc.info/?l=openssh-unix-dev)). Bugs and feature requests are tracked on our [Bugzilla](https://bugzilla.mindrot.org/).
86
87## Reporting bugs
88
89_Non-security_ bugs may be reported to the developers via [Bugzilla](https://bugzilla.mindrot.org/) or via the mailing list above. Security bugs should be reported to [openssh@openssh.com](mailto:openssh.openssh.com).
90
README.platform
1This file contains notes about OpenSSH on specific platforms.
2
3AIX
4
5Beginning with OpenSSH 3.8p1, sshd will honour an account's password
6expiry settings, where prior to that it did not. Because of this,
7it's possible for sites that have used OpenSSH's sshd exclusively to
8have accounts which have passwords expired longer than the inactive time
9(ie the "Weeks between password EXPIRATION and LOCKOUT" setting in SMIT
10or the maxexpired chuser attribute).
11
12Accounts in this state must have their passwords reset manually by the
13administrator. As a precaution, it is recommended that the administrative
14passwords be reset before upgrading from OpenSSH <3.8.
15
16As of OpenSSH 4.0p1, configure will attempt to detect if your version
17and maintenance level of AIX has a working getaddrinfo, and will use it
18if found. This will enable IPv6 support. If for some reason configure
19gets it wrong, or if you want to build binaries to work on earlier MLs
20than the build host then you can add "-DBROKEN_GETADDRINFO" to CFLAGS
21to force the previous IPv4-only behaviour.
22
23IPv6 known to work: 5.1ML7 5.2ML2 5.2ML5
24IPv6 known broken: 4.3.3ML11 5.1ML4
25
26If you wish to use dynamic libraries that aren't in the normal system
27locations (eg IBM's OpenSSL and zlib packages) then you will need to
28define the environment variable blibpath before running configure, eg
29
30blibpath=/lib:/usr/lib:/opt/freeware/lib ./configure \
31 --with-ssl-dir=/opt/freeware --with-zlib=/opt/freeware
32
33If sshd is built with the WITH_AIXAUTHENTICATE option (which is enabled
34by default) then sshd checks that users are permitted via the
35loginrestrictions() function, in particular that the user has the
36"rlogin" attribute set. This check is not done for the root account,
37instead the PermitRootLogin setting in sshd_config is used.
38
39If you are using the IBM compiler you probably want to use CC=xlc rather
40than the default of cc.
41
42
43Cygwin
44------
45To build on Cygwin, OpenSSH requires the following packages:
46gcc, gcc-mingw-core, mingw-runtime, binutils, make, openssl,
47openssl-devel, zlib, minres, minires-devel.
48
49
50Darwin and MacOS X
51------------------
52Darwin does not provide a tun(4) driver required for OpenSSH-based
53virtual private networks. The BSD manpage still exists, but the driver
54has been removed in recent releases of Darwin and MacOS X.
55
56Tunnel support is known to work with Darwin 8 and MacOS X 10.4 in
57Point-to-Point (Layer 3) and Ethernet (Layer 2) mode using a third
58party driver. More information is available at:
59 https://tuntaposx.sourceforge.net
60
61Recent Darwin/MacOS X versions are likely unsupported.
62
63Linux
64-----
65
66Some Linux distributions (including Red Hat/Fedora/CentOS) include
67headers and library links in the -devel RPMs rather than the main
68binary RPMs. If you get an error about headers, or complaining about a
69missing prerequisite then you may need to install the equivalent
70development packages. On Redhat based distros these may be openssl-devel,
71zlib-devel and pam-devel, on Debian based distros these may be
72libssl-dev, libz-dev and libpam-dev.
73
74
75Solaris
76-------
77If you enable BSM auditing on Solaris, you need to update audit_event(4)
78for praudit(1m) to give sensible output. The following line needs to be
79added to /etc/security/audit_event:
80
81 32800:AUE_openssh:OpenSSH login:lo
82
83The BSM audit event range available for third party TCB applications is
8432768 - 65535. Event number 32800 has been chosen for AUE_openssh.
85There is no official registry of 3rd party event numbers, so if this
86number is already in use on your system, you may change it at build time
87by configure'ing --with-cflags=-DAUE_openssh=32801 then rebuilding.
88
89
90Platforms using PAM
91-------------------
92As of OpenSSH 4.3p1, sshd will no longer check /etc/nologin itself when
93PAM is enabled. To maintain existing behaviour, pam_nologin should be
94added to sshd's session stack which will prevent users from starting shell
95sessions. Alternatively, pam_nologin can be added to either the auth or
96account stacks which will prevent authentication entirely, but will still
97return the output from pam_nologin to the client.
98
README.privsep
1Privilege separation, or privsep, is a method in OpenSSH by which
2operations that require root privilege are performed by a separate
3privileged monitor process. Its purpose is to prevent privilege
4escalation and mitigate attacks by:
5
6 - reducing the privileged attack surface by performing most
7 operations involving untrusted data in unprivileged code,
8 - facilitating OS-level sandboxing of the components that are most
9 exposed to attack,
10 - reducing information-sharing between privileged and
11 unprivileged code, and
12 - containing attacks as much as possible to the unprivileged
13 process, should they occur.
14
15To achieve privilege separation in OpenSSH's sshd, the functions
16it performs are split across three discrete binaries:
17
18sshd is the main entry-point binary for the server. This binary
19retains privilege but performs a very limited set of tasks: loading
20and checking the configuration, listening for incoming connections
21and monitoring the status of connections through the
22pre-authentication phase of their lifecycle to implement the
23MaxStartups and PerSourcePenalties features.
24
25Apart from listening for and accepting connections, the sshd binary
26does not handle untrusted, network-derived data; instead it forks and
27executes the sshd-session binary for each new connection.
28
29+---------------------------------------------------------------+
30| |
31| listening socket +-------------------+ |
32| \--------------+ sshd (listener) | |
33| +--------++---------+ |
34| || |
35| || fork+exec |
36| || |
37| +--------------++------------------+ |
38| | sshd-session (preauth monitor) | |
39| +--------------++------------------+ |
40| || |
41| || fork+exec |
42| || |
43| network socket +------------++--------------+ |
44| \-----------+ sshd-auth (unprivileged) | |
45| +------------++--------------+ |
46| |
47+---------------------------------------------------------------+
48 pre-authentication process structure
49
50sshd-session initially acts as the privileged monitor process for
51a connection before it completes authentication. During this phase,
52it does not deal directly with network-derived data, but forks and
53executes a third binary (sshd-auth, described next) to handle the
54SSH protocol communication over the network socket. sshd-session
55receives RPC messages from the sshd-auth subprocess when it needs
56to perform privileged operations, such as verifying an account's
57existence, signing with a host key, or checking a user's password.
58The monitor process implements a loose state machine that enforces
59the required structure and order of operations that sshd-auth may
60request.
61
62sshd-auth is the network-facing process that implements the initial
63key agreement and authentication phase of the SSH protocol. It is
64started with privilege, but will sandbox and/or chroot(2) itself
65and drop privilege to an unprivileged account before processing
66any network traffic. All operations that require privilege, such as
67looking up user information, private key signatures, checking
68passwords, etc are performed by RPC to the parent sshd-session
69process. After authentication completes, sshd-auth serialises its
70SSH protocol and connection state, exports this to the parent
71sshd-session process and exits.
72
73Communication between parent and child processes occurs over shared
74file descriptors. Parent processes also monitor their children for
75abnormal exit conditions, such as crashes or signalling via exit(3)
76status. These conditions are used in sshd to implement the
77PerSourcePenalties controls.
78
79+---------------------------------------------------------------+
80| |
81| +---------------++------------------+ |
82| | sshd-session (postauth monitor) | |
83| +---------------++------------------+ |
84| || |
85| || fork |
86| || |
87| network socket +--------------++---------------+ |
88| \-----------+ sshd-session (unprivileged) | |
89| +--------------++---------------+ |
90| |
91+---------------------------------------------------------------+
92 post-authentication process structure
93
94After authentication, sshd-session disconnects from its parent
95listener sshd (which doesn't track connections after authentication
96has succeeded) and forks again. The forked sshd-session child process
97will drop privilege to that of the authenticated user, import the
98previously-serialised connection state from sshd-auth and continue to
99perform network and SSH protocol operations for the remainder of the
100session.
101
102The parent sshd-session process continues to act as a privileged
103monitor process, performing actions that require privilege when
104requested via RPC. These operations include allocating PTYs and
105signing key re-exchange messages.
106
107In portable OpenSSH several compile-time options affect privilege
108separation:
109
110 --with-sandbox=style
111
112Controls the sandboxing implementation used by sshd-auth. OS level
113sandboxing is supported on a number of platforms. A fallback
114rlimit(2)-based sandbox provides some basic control on a wider set
115of platforms. Most supported sandboxes are detected and enabled
116automatically, so this option is mostly used to disable the sandbox
117(this is handy when debugging or running under tools like
118AddressSanitizer).
119
120 --with-privsep-user=user
121
122Specifies the unprivileged user that sshd-auth will switch to
123before it starts handling untrusted data. This user must not be
124shared with any other system service, should own no files, should
125have a locked password, a shell that denies access (such as
126/bin/nologin or /bin/false) and the home directory set to the
127privilege separation path. For most platforms the default user is
128"sshd".
129
130 --with-privsep-path=/path
131
132Controls the directory that sshd-auth will chroot(2) to before
133dropping privileges. This directory should be empty, not shared
134with other system accounts and not readable or writable by the
135sandbox user. The default privsep path is "/var/empty".
136
137You should do something like the following to prepare the privsep
138preauth environment:
139
140 # mkdir /var/empty
141 # chown root:sys /var/empty
142 # chmod 755 /var/empty
143 # groupadd sshd
144 # useradd -g sshd -c 'sshd privsep' -d /var/empty -s /bin/false sshd
145
146On some platforms, only the pre-authentication part of privsep is
147supported, and the post-authentication part is disabled due to lack
148of support from the operating system.
149
150This is an example process list for a connection in the
151pre-authentication phase:
152
153 PID PPID UID CMD
154
155 1436 1 0 sshd: /usr/sbin/sshd -D [listener] 1 of 10-100 startups
156 47077 1436 0 sshd-session: djm [priv]
157 47078 47077 107 sshd-auth: djm [net]
158
159Where process 1436 is the listener, 47077 is the privileged
160sshd-session monitor process and 47078 is the unprivileged,
161network-facing sshd-auth process.
162
163And in the post-authentication phase:
164
165 PID PPID UID CMD
166 47077 1436 0 sshd-session: djm [priv]
167 47091 47077 1000 sshd-session: djm@pts/1
168 47092 47091 1000 -bash
169
170Where process 47077 continues its role as a privileged monitor,
17147091 is the user-privileged network-facing post-authentication
172process and 47092 is the user shell started for the session.
173
174
README.tun
1How to use OpenSSH-based virtual private networks
2-------------------------------------------------
3
4OpenSSH contains support for VPN tunneling using the tun(4) network
5tunnel pseudo-device which is available on most platforms, either for
6layer 2 or 3 traffic.
7
8The following brief instructions on how to use this feature use
9a network configuration specific to the OpenBSD operating system.
10
11(1) Server: Enable support for SSH tunneling
12
13To enable the ssh server to accept tunnel requests from the client, you
14have to add the following option to the ssh server configuration file
15(/etc/ssh/sshd_config):
16
17 PermitTunnel yes
18
19Restart the server or send the hangup signal (SIGHUP) to let the server
20reread it's configuration.
21
22(2) Server: Restrict client access and assign the tunnel
23
24The OpenSSH server simply uses the file /root/.ssh/authorized_keys to
25restrict the client to connect to a specified tunnel and to
26automatically start the related interface configuration command. These
27settings are optional but recommended:
28
29 tunnel="1",command="sh /etc/netstart tun1" ssh-rsa ... reyk@openbsd.org
30
31(3) Client: Configure the local network tunnel interface
32
33Use the hostname.if(5) interface-specific configuration file to set up
34the network tunnel configuration with OpenBSD. For example, use the
35following configuration in /etc/hostname.tun0 to set up the layer 3
36tunnel on the client:
37
38 inet 192.168.5.1 255.255.255.252 192.168.5.2
39
40OpenBSD also supports layer 2 tunneling over the tun device by adding
41the link0 flag:
42
43 inet 192.168.1.78 255.255.255.0 192.168.1.255 link0
44
45Layer 2 tunnels can be used in combination with an Ethernet bridge(4)
46interface, like the following example for /etc/bridgename.bridge0:
47
48 add tun0
49 add sis0
50 up
51
52(4) Client: Configure the OpenSSH client
53
54To establish tunnel forwarding for connections to a specified
55remote host by default, use the following ssh client configuration for
56the privileged user (in /root/.ssh/config):
57
58 Host sshgateway
59 Tunnel yes
60 TunnelDevice 0:any
61 PermitLocalCommand yes
62 LocalCommand sh /etc/netstart tun0
63
64A more complicated configuration is possible to establish a tunnel to
65a remote host which is not directly accessible by the client.
66The following example describes a client configuration to connect to
67the remote host over two ssh hops in between. It uses the OpenSSH
68ProxyCommand in combination with the nc(1) program to forward the final
69ssh tunnel destination over multiple ssh sessions.
70
71 Host access.somewhere.net
72 User puffy
73 Host dmzgw
74 User puffy
75 ProxyCommand ssh access.somewhere.net nc dmzgw 22
76 Host sshgateway
77 Tunnel Ethernet
78 TunnelDevice 0:any
79 PermitLocalCommand yes
80 LocalCommand sh /etc/netstart tun0
81 ProxyCommand ssh dmzgw nc sshgateway 22
82
83The following network plan illustrates the previous configuration in
84combination with layer 2 tunneling and Ethernet bridging.
85
86+--------+ ( ) +----------------------+
87| Client |------( Internet )-----| access.somewhere.net |
88+--------+ ( ) +----------------------+
89 : 192.168.1.78 |
90 :............................. +-------+
91 Forwarded ssh connection : | dmzgw |
92 Layer 2 tunnel : +-------+
93 : |
94 : |
95 : +------------+
96 :......| sshgateway |
97 | +------------+
98--- real connection Bridge -> | +----------+
99... "virtual connection" [ X ]--------| somehost |
100[X] switch +----------+
101 192.168.1.25
102
103(5) Client: Connect to the server and establish the tunnel
104
105Finally connect to the OpenSSH server to establish the tunnel by using
106the following command:
107
108 ssh sshgateway
109
110It is also possible to tell the client to fork into the background after
111the connection has been successfully established:
112
113 ssh -f sshgateway true
114
115Without the ssh configuration done in step (4), it is also possible
116to use the following command lines:
117
118 ssh -fw 0:1 sshgateway true
119 ifconfig tun0 192.168.5.1 192.168.5.2 netmask 255.255.255.252
120
121Using OpenSSH tunnel forwarding is a simple way to establish secure
122and ad hoc virtual private networks. Possible fields of application
123could be wireless networks or administrative VPN tunnels.
124
125Nevertheless, ssh tunneling requires some packet header overhead and
126runs on top of TCP. It is still suggested to use the IP Security
127Protocol (IPSec) for robust and permanent VPN connections and to
128interconnect corporate networks.
129
130 Reyk Floeter
131
132$OpenBSD: README.tun,v 1.4 2006/03/28 00:12:31 deraadt Exp $
133