xref: /freebsd/crypto/openssh/ssh.h (revision 9336e0699bda8a301cd2bfa37106b6ec5e32012e)
1 /* $OpenBSD: ssh.h,v 1.78 2006/08/03 03:34:42 deraadt Exp $ */
2 
3 /*
4  * Author: Tatu Ylonen <ylo@cs.hut.fi>
5  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
6  *                    All rights reserved
7  *
8  * As far as I am concerned, the code I have written for this software
9  * can be used freely for any purpose.  Any derived versions of this
10  * software must be clearly marked as such, and if the derived work is
11  * incompatible with the protocol description in the RFC file, it must be
12  * called by a name other than "ssh" or "Secure Shell".
13  */
14 
15 /* Cipher used for encrypting authentication files. */
16 #define SSH_AUTHFILE_CIPHER	SSH_CIPHER_3DES
17 
18 /* Default port number. */
19 #define SSH_DEFAULT_PORT	22
20 
21 /* Maximum number of TCP/IP ports forwarded per direction. */
22 #define SSH_MAX_FORWARDS_PER_DIRECTION	100
23 
24 /*
25  * Maximum number of RSA authentication identity files that can be specified
26  * in configuration files or on the command line.
27  */
28 #define SSH_MAX_IDENTITY_FILES		100
29 
30 /*
31  * Maximum length of lines in authorized_keys file.
32  * Current value permits 16kbit RSA and RSA1 keys and 8kbit DSA keys, with
33  * some room for options and comments.
34  */
35 #define SSH_MAX_PUBKEY_BYTES		8192
36 
37 /*
38  * Major protocol version.  Different version indicates major incompatibility
39  * that prevents communication.
40  *
41  * Minor protocol version.  Different version indicates minor incompatibility
42  * that does not prevent interoperation.
43  */
44 #define PROTOCOL_MAJOR_1	1
45 #define PROTOCOL_MINOR_1	5
46 
47 /* We support both SSH1 and SSH2 */
48 #define PROTOCOL_MAJOR_2	2
49 #define PROTOCOL_MINOR_2	0
50 
51 /*
52  * Name for the service.  The port named by this service overrides the
53  * default port if present.
54  */
55 #define SSH_SERVICE_NAME	"ssh"
56 
57 /*
58  * Name of the environment variable containing the process ID of the
59  * authentication agent.
60  */
61 #define SSH_AGENTPID_ENV_NAME	"SSH_AGENT_PID"
62 
63 /*
64  * Name of the environment variable containing the pathname of the
65  * authentication socket.
66  */
67 #define SSH_AUTHSOCKET_ENV_NAME "SSH_AUTH_SOCK"
68 
69 /*
70  * Environment variable for overwriting the default location of askpass
71  */
72 #define SSH_ASKPASS_ENV		"SSH_ASKPASS"
73 
74 /*
75  * Force host key length and server key length to differ by at least this
76  * many bits.  This is to make double encryption with rsaref work.
77  */
78 #define SSH_KEY_BITS_RESERVED		128
79 
80 /*
81  * Length of the session key in bytes.  (Specified as 256 bits in the
82  * protocol.)
83  */
84 #define SSH_SESSION_KEY_LENGTH		32
85 
86 /* Used to identify ``EscapeChar none'' */
87 #define SSH_ESCAPECHAR_NONE		-2
88 
89 /*
90  * unprivileged user when UsePrivilegeSeparation=yes;
91  * sshd will change its privileges to this user and its
92  * primary group.
93  */
94 #ifndef SSH_PRIVSEP_USER
95 #define SSH_PRIVSEP_USER		"sshd"
96 #endif
97 
98 /* Minimum modulus size (n) for RSA keys. */
99 #define SSH_RSA_MINIMUM_MODULUS_SIZE	768
100 
101 /* Listen backlog for sshd, ssh-agent and forwarding sockets */
102 #define SSH_LISTEN_BACKLOG		128
103