1545d5ecaSDag-Erling Smørgrav.\" 2545d5ecaSDag-Erling Smørgrav.\" Author: Tatu Ylonen <ylo@cs.hut.fi> 3545d5ecaSDag-Erling Smørgrav.\" Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland 4545d5ecaSDag-Erling Smørgrav.\" All rights reserved 5545d5ecaSDag-Erling Smørgrav.\" 6545d5ecaSDag-Erling Smørgrav.\" As far as I am concerned, the code I have written for this software 7545d5ecaSDag-Erling Smørgrav.\" can be used freely for any purpose. Any derived versions of this 8545d5ecaSDag-Erling Smørgrav.\" software must be clearly marked as such, and if the derived work is 9545d5ecaSDag-Erling Smørgrav.\" incompatible with the protocol description in the RFC file, it must be 10545d5ecaSDag-Erling Smørgrav.\" called by a name other than "ssh" or "Secure Shell". 11545d5ecaSDag-Erling Smørgrav.\" 12545d5ecaSDag-Erling Smørgrav.\" Copyright (c) 1999,2000 Markus Friedl. All rights reserved. 13545d5ecaSDag-Erling Smørgrav.\" Copyright (c) 1999 Aaron Campbell. All rights reserved. 14545d5ecaSDag-Erling Smørgrav.\" Copyright (c) 1999 Theo de Raadt. All rights reserved. 15545d5ecaSDag-Erling Smørgrav.\" 16545d5ecaSDag-Erling Smørgrav.\" Redistribution and use in source and binary forms, with or without 17545d5ecaSDag-Erling Smørgrav.\" modification, are permitted provided that the following conditions 18545d5ecaSDag-Erling Smørgrav.\" are met: 19545d5ecaSDag-Erling Smørgrav.\" 1. Redistributions of source code must retain the above copyright 20545d5ecaSDag-Erling Smørgrav.\" notice, this list of conditions and the following disclaimer. 21545d5ecaSDag-Erling Smørgrav.\" 2. Redistributions in binary form must reproduce the above copyright 22545d5ecaSDag-Erling Smørgrav.\" notice, this list of conditions and the following disclaimer in the 23545d5ecaSDag-Erling Smørgrav.\" documentation and/or other materials provided with the distribution. 24545d5ecaSDag-Erling Smørgrav.\" 25545d5ecaSDag-Erling Smørgrav.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 26545d5ecaSDag-Erling Smørgrav.\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 27545d5ecaSDag-Erling Smørgrav.\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 28545d5ecaSDag-Erling Smørgrav.\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 29545d5ecaSDag-Erling Smørgrav.\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 30545d5ecaSDag-Erling Smørgrav.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 31545d5ecaSDag-Erling Smørgrav.\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 32545d5ecaSDag-Erling Smørgrav.\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 33545d5ecaSDag-Erling Smørgrav.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 34545d5ecaSDag-Erling Smørgrav.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 35545d5ecaSDag-Erling Smørgrav.\" 366888a9beSDag-Erling Smørgrav.\" $OpenBSD: sshd_config.5,v 1.156 2013/02/06 00:20:42 dtucker Exp $ 3735d4ccfbSDag-Erling Smørgrav.\" $FreeBSD$ 386888a9beSDag-Erling Smørgrav.Dd February 6, 2013 39545d5ecaSDag-Erling Smørgrav.Dt SSHD_CONFIG 5 40545d5ecaSDag-Erling Smørgrav.Os 41545d5ecaSDag-Erling Smørgrav.Sh NAME 42545d5ecaSDag-Erling Smørgrav.Nm sshd_config 43545d5ecaSDag-Erling Smørgrav.Nd OpenSSH SSH daemon configuration file 44545d5ecaSDag-Erling Smørgrav.Sh SYNOPSIS 45d4af9e69SDag-Erling Smørgrav.Nm /etc/ssh/sshd_config 46545d5ecaSDag-Erling Smørgrav.Sh DESCRIPTION 47333ee039SDag-Erling Smørgrav.Xr sshd 8 48545d5ecaSDag-Erling Smørgravreads configuration data from 49545d5ecaSDag-Erling Smørgrav.Pa /etc/ssh/sshd_config 50545d5ecaSDag-Erling Smørgrav(or the file specified with 51545d5ecaSDag-Erling Smørgrav.Fl f 52545d5ecaSDag-Erling Smørgravon the command line). 53545d5ecaSDag-Erling SmørgravThe file contains keyword-argument pairs, one per line. 54545d5ecaSDag-Erling SmørgravLines starting with 55545d5ecaSDag-Erling Smørgrav.Ql # 56545d5ecaSDag-Erling Smørgravand empty lines are interpreted as comments. 57333ee039SDag-Erling SmørgravArguments may optionally be enclosed in double quotes 58333ee039SDag-Erling Smørgrav.Pq \&" 59333ee039SDag-Erling Smørgravin order to represent arguments containing spaces. 60545d5ecaSDag-Erling Smørgrav.Pp 61545d5ecaSDag-Erling SmørgravThe possible 62545d5ecaSDag-Erling Smørgravkeywords and their meanings are as follows (note that 63545d5ecaSDag-Erling Smørgravkeywords are case-insensitive and arguments are case-sensitive): 64545d5ecaSDag-Erling Smørgrav.Bl -tag -width Ds 6521e764dfSDag-Erling Smørgrav.It Cm AcceptEnv 6621e764dfSDag-Erling SmørgravSpecifies what environment variables sent by the client will be copied into 6721e764dfSDag-Erling Smørgravthe session's 6821e764dfSDag-Erling Smørgrav.Xr environ 7 . 6921e764dfSDag-Erling SmørgravSee 7021e764dfSDag-Erling Smørgrav.Cm SendEnv 7121e764dfSDag-Erling Smørgravin 7221e764dfSDag-Erling Smørgrav.Xr ssh_config 5 7321e764dfSDag-Erling Smørgravfor how to configure the client. 7421e764dfSDag-Erling SmørgravNote that environment passing is only supported for protocol 2. 7521e764dfSDag-Erling SmørgravVariables are specified by name, which may contain the wildcard characters 76333ee039SDag-Erling Smørgrav.Ql * 7721e764dfSDag-Erling Smørgravand 7821e764dfSDag-Erling Smørgrav.Ql \&? . 7921e764dfSDag-Erling SmørgravMultiple environment variables may be separated by whitespace or spread 8021e764dfSDag-Erling Smørgravacross multiple 8121e764dfSDag-Erling Smørgrav.Cm AcceptEnv 8221e764dfSDag-Erling Smørgravdirectives. 8321e764dfSDag-Erling SmørgravBe warned that some environment variables could be used to bypass restricted 8421e764dfSDag-Erling Smørgravuser environments. 8521e764dfSDag-Erling SmørgravFor this reason, care should be taken in the use of this directive. 8621e764dfSDag-Erling SmørgravThe default is not to accept any environment variables. 87aa49c926SDag-Erling Smørgrav.It Cm AddressFamily 88aa49c926SDag-Erling SmørgravSpecifies which address family should be used by 89333ee039SDag-Erling Smørgrav.Xr sshd 8 . 90aa49c926SDag-Erling SmørgravValid arguments are 91aa49c926SDag-Erling Smørgrav.Dq any , 92aa49c926SDag-Erling Smørgrav.Dq inet 93333ee039SDag-Erling Smørgrav(use IPv4 only), or 94aa49c926SDag-Erling Smørgrav.Dq inet6 95aa49c926SDag-Erling Smørgrav(use IPv6 only). 96aa49c926SDag-Erling SmørgravThe default is 97aa49c926SDag-Erling Smørgrav.Dq any . 98d4af9e69SDag-Erling Smørgrav.It Cm AllowAgentForwarding 99d4af9e69SDag-Erling SmørgravSpecifies whether 100d4af9e69SDag-Erling Smørgrav.Xr ssh-agent 1 101d4af9e69SDag-Erling Smørgravforwarding is permitted. 102d4af9e69SDag-Erling SmørgravThe default is 103d4af9e69SDag-Erling Smørgrav.Dq yes . 104d4af9e69SDag-Erling SmørgravNote that disabling agent forwarding does not improve security 105d4af9e69SDag-Erling Smørgravunless users are also denied shell access, as they can always install 106d4af9e69SDag-Erling Smørgravtheir own forwarders. 107545d5ecaSDag-Erling Smørgrav.It Cm AllowGroups 108545d5ecaSDag-Erling SmørgravThis keyword can be followed by a list of group name patterns, separated 109545d5ecaSDag-Erling Smørgravby spaces. 110545d5ecaSDag-Erling SmørgravIf specified, login is allowed only for users whose primary 111545d5ecaSDag-Erling Smørgravgroup or supplementary group list matches one of the patterns. 112545d5ecaSDag-Erling SmørgravOnly group names are valid; a numerical group ID is not recognized. 113545d5ecaSDag-Erling SmørgravBy default, login is allowed for all groups. 114333ee039SDag-Erling SmørgravThe allow/deny directives are processed in the following order: 115333ee039SDag-Erling Smørgrav.Cm DenyUsers , 116333ee039SDag-Erling Smørgrav.Cm AllowUsers , 117333ee039SDag-Erling Smørgrav.Cm DenyGroups , 118333ee039SDag-Erling Smørgravand finally 119333ee039SDag-Erling Smørgrav.Cm AllowGroups . 120333ee039SDag-Erling Smørgrav.Pp 121333ee039SDag-Erling SmørgravSee 122333ee039SDag-Erling Smørgrav.Sx PATTERNS 123333ee039SDag-Erling Smørgravin 124333ee039SDag-Erling Smørgrav.Xr ssh_config 5 125333ee039SDag-Erling Smørgravfor more information on patterns. 126545d5ecaSDag-Erling Smørgrav.It Cm AllowTcpForwarding 127545d5ecaSDag-Erling SmørgravSpecifies whether TCP forwarding is permitted. 1286888a9beSDag-Erling SmørgravThe available options are 1296888a9beSDag-Erling Smørgrav.Dq yes 1306888a9beSDag-Erling Smørgravor 1316888a9beSDag-Erling Smørgrav.Dq all 1326888a9beSDag-Erling Smørgravto allow TCP forwarding, 1336888a9beSDag-Erling Smørgrav.Dq no 1346888a9beSDag-Erling Smørgravto prevent all TCP forwarding, 1356888a9beSDag-Erling Smørgrav.Dq local 1366888a9beSDag-Erling Smørgravto allow local (from the perspective of 1376888a9beSDag-Erling Smørgrav.Xr ssh 1 ) 1386888a9beSDag-Erling Smørgravforwarding only or 1396888a9beSDag-Erling Smørgrav.Dq remote 1406888a9beSDag-Erling Smørgravto allow remote forwarding only. 141545d5ecaSDag-Erling SmørgravThe default is 142545d5ecaSDag-Erling Smørgrav.Dq yes . 143545d5ecaSDag-Erling SmørgravNote that disabling TCP forwarding does not improve security unless 144545d5ecaSDag-Erling Smørgravusers are also denied shell access, as they can always install their 145545d5ecaSDag-Erling Smørgravown forwarders. 146545d5ecaSDag-Erling Smørgrav.It Cm AllowUsers 147545d5ecaSDag-Erling SmørgravThis keyword can be followed by a list of user name patterns, separated 148545d5ecaSDag-Erling Smørgravby spaces. 149e73e9afaSDag-Erling SmørgravIf specified, login is allowed only for user names that 150545d5ecaSDag-Erling Smørgravmatch one of the patterns. 151545d5ecaSDag-Erling SmørgravOnly user names are valid; a numerical user ID is not recognized. 152545d5ecaSDag-Erling SmørgravBy default, login is allowed for all users. 153545d5ecaSDag-Erling SmørgravIf the pattern takes the form USER@HOST then USER and HOST 154545d5ecaSDag-Erling Smørgravare separately checked, restricting logins to particular 155545d5ecaSDag-Erling Smørgravusers from particular hosts. 156333ee039SDag-Erling SmørgravThe allow/deny directives are processed in the following order: 157333ee039SDag-Erling Smørgrav.Cm DenyUsers , 158333ee039SDag-Erling Smørgrav.Cm AllowUsers , 159333ee039SDag-Erling Smørgrav.Cm DenyGroups , 160333ee039SDag-Erling Smørgravand finally 161333ee039SDag-Erling Smørgrav.Cm AllowGroups . 162333ee039SDag-Erling Smørgrav.Pp 163333ee039SDag-Erling SmørgravSee 164333ee039SDag-Erling Smørgrav.Sx PATTERNS 165333ee039SDag-Erling Smørgravin 166333ee039SDag-Erling Smørgrav.Xr ssh_config 5 167333ee039SDag-Erling Smørgravfor more information on patterns. 1686888a9beSDag-Erling Smørgrav.It Cm AuthenticationMethods 1696888a9beSDag-Erling SmørgravSpecifies the authentication methods that must be successfully completed 1706888a9beSDag-Erling Smørgravfor a user to be granted access. 1716888a9beSDag-Erling SmørgravThis option must be followed by one or more comma-separated lists of 1726888a9beSDag-Erling Smørgravauthentication method names. 1736888a9beSDag-Erling SmørgravSuccessful authentication requires completion of every method in at least 1746888a9beSDag-Erling Smørgravone of these lists. 1756888a9beSDag-Erling Smørgrav.Pp 1766888a9beSDag-Erling SmørgravFor example, an argument of 1776888a9beSDag-Erling Smørgrav.Dq publickey,password publickey,keyboard-interactive 1786888a9beSDag-Erling Smørgravwould require the user to complete public key authentication, followed by 1796888a9beSDag-Erling Smørgraveither password or keyboard interactive authentication. 1806888a9beSDag-Erling SmørgravOnly methods that are next in one or more lists are offered at each stage, 1816888a9beSDag-Erling Smørgravso for this example, it would not be possible to attempt password or 1826888a9beSDag-Erling Smørgravkeyboard-interactive authentication before public key. 1836888a9beSDag-Erling Smørgrav.Pp 1846888a9beSDag-Erling SmørgravThis option is only available for SSH protocol 2 and will yield a fatal 1856888a9beSDag-Erling Smørgraverror if enabled if protocol 1 is also enabled. 1866888a9beSDag-Erling SmørgravNote that each authentication method listed should also be explicitly enabled 1876888a9beSDag-Erling Smørgravin the configuration. 1886888a9beSDag-Erling SmørgravThe default is not to require multiple authentication; successful completion 1896888a9beSDag-Erling Smørgravof a single authentication method is sufficient. 1906888a9beSDag-Erling Smørgrav.It Cm AuthorizedKeysCommand 1916888a9beSDag-Erling SmørgravSpecifies a program to be used to look up the user's public keys. 1926888a9beSDag-Erling SmørgravThe program will be invoked with a single argument of the username 1936888a9beSDag-Erling Smørgravbeing authenticated, and should produce on standard output zero or 1946888a9beSDag-Erling Smørgravmore lines of authorized_keys output (see 1956888a9beSDag-Erling Smørgrav.Sx AUTHORIZED_KEYS 1966888a9beSDag-Erling Smørgravin 1976888a9beSDag-Erling Smørgrav.Xr sshd 8 ) . 1986888a9beSDag-Erling SmørgravIf a key supplied by AuthorizedKeysCommand does not successfully authenticate 1996888a9beSDag-Erling Smørgravand authorize the user then public key authentication continues using the usual 2006888a9beSDag-Erling Smørgrav.Cm AuthorizedKeysFile 2016888a9beSDag-Erling Smørgravfiles. 2026888a9beSDag-Erling SmørgravBy default, no AuthorizedKeysCommand is run. 2036888a9beSDag-Erling Smørgrav.It Cm AuthorizedKeysCommandUser 2046888a9beSDag-Erling SmørgravSpecifies the user under whose account the AuthorizedKeysCommand is run. 2056888a9beSDag-Erling SmørgravIt is recommended to use a dedicated user that has no other role on the host 2066888a9beSDag-Erling Smørgravthan running authorized keys commands. 207545d5ecaSDag-Erling Smørgrav.It Cm AuthorizedKeysFile 208545d5ecaSDag-Erling SmørgravSpecifies the file that contains the public keys that can be used 209545d5ecaSDag-Erling Smørgravfor user authentication. 210e2f6069cSDag-Erling SmørgravThe format is described in the 211e2f6069cSDag-Erling Smørgrav.Sx AUTHORIZED_KEYS FILE FORMAT 212e2f6069cSDag-Erling Smørgravsection of 213e2f6069cSDag-Erling Smørgrav.Xr sshd 8 . 214545d5ecaSDag-Erling Smørgrav.Cm AuthorizedKeysFile 215545d5ecaSDag-Erling Smørgravmay contain tokens of the form %T which are substituted during connection 216333ee039SDag-Erling Smørgravsetup. 217cf2b5f3bSDag-Erling SmørgravThe following tokens are defined: %% is replaced by a literal '%', 218333ee039SDag-Erling Smørgrav%h is replaced by the home directory of the user being authenticated, and 219545d5ecaSDag-Erling Smørgrav%u is replaced by the username of that user. 220545d5ecaSDag-Erling SmørgravAfter expansion, 221545d5ecaSDag-Erling Smørgrav.Cm AuthorizedKeysFile 222545d5ecaSDag-Erling Smørgravis taken to be an absolute path or one relative to the user's home 223545d5ecaSDag-Erling Smørgravdirectory. 224e146993eSDag-Erling SmørgravMultiple files may be listed, separated by whitespace. 225545d5ecaSDag-Erling SmørgravThe default is 226e146993eSDag-Erling Smørgrav.Dq .ssh/authorized_keys .ssh/authorized_keys2 . 227e2f6069cSDag-Erling Smørgrav.It Cm AuthorizedPrincipalsFile 228e2f6069cSDag-Erling SmørgravSpecifies a file that lists principal names that are accepted for 229e2f6069cSDag-Erling Smørgravcertificate authentication. 230e2f6069cSDag-Erling SmørgravWhen using certificates signed by a key listed in 231e2f6069cSDag-Erling Smørgrav.Cm TrustedUserCAKeys , 232e2f6069cSDag-Erling Smørgravthis file lists names, one of which must appear in the certificate for it 233e2f6069cSDag-Erling Smørgravto be accepted for authentication. 234e2f6069cSDag-Erling SmørgravNames are listed one per line preceded by key options (as described 235e2f6069cSDag-Erling Smørgravin 236e2f6069cSDag-Erling Smørgrav.Sx AUTHORIZED_KEYS FILE FORMAT 237e2f6069cSDag-Erling Smørgravin 238e2f6069cSDag-Erling Smørgrav.Xr sshd 8 ) . 239e2f6069cSDag-Erling SmørgravEmpty lines and comments starting with 240e2f6069cSDag-Erling Smørgrav.Ql # 241e2f6069cSDag-Erling Smørgravare ignored. 242e2f6069cSDag-Erling Smørgrav.Pp 243e2f6069cSDag-Erling Smørgrav.Cm AuthorizedPrincipalsFile 244e2f6069cSDag-Erling Smørgravmay contain tokens of the form %T which are substituted during connection 245e2f6069cSDag-Erling Smørgravsetup. 246e2f6069cSDag-Erling SmørgravThe following tokens are defined: %% is replaced by a literal '%', 247e2f6069cSDag-Erling Smørgrav%h is replaced by the home directory of the user being authenticated, and 248e2f6069cSDag-Erling Smørgrav%u is replaced by the username of that user. 249e2f6069cSDag-Erling SmørgravAfter expansion, 250e2f6069cSDag-Erling Smørgrav.Cm AuthorizedPrincipalsFile 251e2f6069cSDag-Erling Smørgravis taken to be an absolute path or one relative to the user's home 252e2f6069cSDag-Erling Smørgravdirectory. 253e2f6069cSDag-Erling Smørgrav.Pp 254462c32cbSDag-Erling SmørgravThe default is 255462c32cbSDag-Erling Smørgrav.Dq none , 256462c32cbSDag-Erling Smørgravi.e. not to use a principals file \(en in this case, the username 257e2f6069cSDag-Erling Smørgravof the user must appear in a certificate's principals list for it to be 258e2f6069cSDag-Erling Smørgravaccepted. 259e2f6069cSDag-Erling SmørgravNote that 260e2f6069cSDag-Erling Smørgrav.Cm AuthorizedPrincipalsFile 261e2f6069cSDag-Erling Smørgravis only used when authentication proceeds using a CA listed in 262e2f6069cSDag-Erling Smørgrav.Cm TrustedUserCAKeys 263e2f6069cSDag-Erling Smørgravand is not consulted for certification authorities trusted via 264e2f6069cSDag-Erling Smørgrav.Pa ~/.ssh/authorized_keys , 265e2f6069cSDag-Erling Smørgravthough the 266e2f6069cSDag-Erling Smørgrav.Cm principals= 267e2f6069cSDag-Erling Smørgravkey option offers a similar facility (see 268e2f6069cSDag-Erling Smørgrav.Xr sshd 8 269e2f6069cSDag-Erling Smørgravfor details). 270545d5ecaSDag-Erling Smørgrav.It Cm Banner 271545d5ecaSDag-Erling SmørgravThe contents of the specified file are sent to the remote user before 272545d5ecaSDag-Erling Smørgravauthentication is allowed. 273d4af9e69SDag-Erling SmørgravIf the argument is 274d4af9e69SDag-Erling Smørgrav.Dq none 275d4af9e69SDag-Erling Smørgravthen no banner is displayed. 276545d5ecaSDag-Erling SmørgravThis option is only available for protocol version 2. 277545d5ecaSDag-Erling SmørgravBy default, no banner is displayed. 278545d5ecaSDag-Erling Smørgrav.It Cm ChallengeResponseAuthentication 2797aee6ffeSDag-Erling SmørgravSpecifies whether challenge-response authentication is allowed (e.g. via 2807aee6ffeSDag-Erling SmørgravPAM or though authentication styles supported in 2817aee6ffeSDag-Erling Smørgrav.Xr login.conf 5 ) 282545d5ecaSDag-Erling SmørgravThe default is 283545d5ecaSDag-Erling Smørgrav.Dq yes . 284d4af9e69SDag-Erling Smørgrav.It Cm ChrootDirectory 285b15c8340SDag-Erling SmørgravSpecifies the pathname of a directory to 286d4af9e69SDag-Erling Smørgrav.Xr chroot 2 287d4af9e69SDag-Erling Smørgravto after authentication. 288b15c8340SDag-Erling SmørgravAll components of the pathname must be root-owned directories that are 289d4af9e69SDag-Erling Smørgravnot writable by any other user or group. 2907aee6ffeSDag-Erling SmørgravAfter the chroot, 2917aee6ffeSDag-Erling Smørgrav.Xr sshd 8 2927aee6ffeSDag-Erling Smørgravchanges the working directory to the user's home directory. 293d4af9e69SDag-Erling Smørgrav.Pp 294b15c8340SDag-Erling SmørgravThe pathname may contain the following tokens that are expanded at runtime once 295d4af9e69SDag-Erling Smørgravthe connecting user has been authenticated: %% is replaced by a literal '%', 296d4af9e69SDag-Erling Smørgrav%h is replaced by the home directory of the user being authenticated, and 297d4af9e69SDag-Erling Smørgrav%u is replaced by the username of that user. 298d4af9e69SDag-Erling Smørgrav.Pp 299d4af9e69SDag-Erling SmørgravThe 300d4af9e69SDag-Erling Smørgrav.Cm ChrootDirectory 301d4af9e69SDag-Erling Smørgravmust contain the necessary files and directories to support the 3027aee6ffeSDag-Erling Smørgravuser's session. 303d4af9e69SDag-Erling SmørgravFor an interactive session this requires at least a shell, typically 304d4af9e69SDag-Erling Smørgrav.Xr sh 1 , 305d4af9e69SDag-Erling Smørgravand basic 306d4af9e69SDag-Erling Smørgrav.Pa /dev 307d4af9e69SDag-Erling Smørgravnodes such as 308d4af9e69SDag-Erling Smørgrav.Xr null 4 , 309d4af9e69SDag-Erling Smørgrav.Xr zero 4 , 310d4af9e69SDag-Erling Smørgrav.Xr stdin 4 , 311d4af9e69SDag-Erling Smørgrav.Xr stdout 4 , 312d4af9e69SDag-Erling Smørgrav.Xr stderr 4 , 313d4af9e69SDag-Erling Smørgrav.Xr arandom 4 314d4af9e69SDag-Erling Smørgravand 315d4af9e69SDag-Erling Smørgrav.Xr tty 4 316d4af9e69SDag-Erling Smørgravdevices. 317d4af9e69SDag-Erling SmørgravFor file transfer sessions using 318d4af9e69SDag-Erling Smørgrav.Dq sftp , 319d4af9e69SDag-Erling Smørgravno additional configuration of the environment is necessary if the 3207aee6ffeSDag-Erling Smørgravin-process sftp server is used, 3217aee6ffeSDag-Erling Smørgravthough sessions which use logging do require 3227aee6ffeSDag-Erling Smørgrav.Pa /dev/log 3237aee6ffeSDag-Erling Smørgravinside the chroot directory (see 3247aee6ffeSDag-Erling Smørgrav.Xr sftp-server 8 325d4af9e69SDag-Erling Smørgravfor details). 326d4af9e69SDag-Erling Smørgrav.Pp 327d4af9e69SDag-Erling SmørgravThe default is not to 328d4af9e69SDag-Erling Smørgrav.Xr chroot 2 . 329545d5ecaSDag-Erling Smørgrav.It Cm Ciphers 330545d5ecaSDag-Erling SmørgravSpecifies the ciphers allowed for protocol version 2. 331545d5ecaSDag-Erling SmørgravMultiple ciphers must be comma-separated. 33221e764dfSDag-Erling SmørgravThe supported ciphers are 33321e764dfSDag-Erling Smørgrav.Dq 3des-cbc , 33421e764dfSDag-Erling Smørgrav.Dq aes128-cbc , 33521e764dfSDag-Erling Smørgrav.Dq aes192-cbc , 33621e764dfSDag-Erling Smørgrav.Dq aes256-cbc , 33721e764dfSDag-Erling Smørgrav.Dq aes128-ctr , 33821e764dfSDag-Erling Smørgrav.Dq aes192-ctr , 33921e764dfSDag-Erling Smørgrav.Dq aes256-ctr , 3406888a9beSDag-Erling Smørgrav.Dq aes128-gcm@openssh.com , 3416888a9beSDag-Erling Smørgrav.Dq aes256-gcm@openssh.com , 342d4ecd108SDag-Erling Smørgrav.Dq arcfour128 , 343d4ecd108SDag-Erling Smørgrav.Dq arcfour256 , 34421e764dfSDag-Erling Smørgrav.Dq arcfour , 34521e764dfSDag-Erling Smørgrav.Dq blowfish-cbc , 34621e764dfSDag-Erling Smørgravand 34721e764dfSDag-Erling Smørgrav.Dq cast128-cbc . 348333ee039SDag-Erling SmørgravThe default is: 349333ee039SDag-Erling Smørgrav.Bd -literal -offset 3n 350cce7d346SDag-Erling Smørgravaes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128, 3516888a9beSDag-Erling Smørgravaes128-gcm@openssh.com,aes256-gcm@openssh.com, 352cce7d346SDag-Erling Smørgravaes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc, 353cce7d346SDag-Erling Smørgravaes256-cbc,arcfour 354545d5ecaSDag-Erling Smørgrav.Ed 355545d5ecaSDag-Erling Smørgrav.It Cm ClientAliveCountMax 356b74df5b2SDag-Erling SmørgravSets the number of client alive messages (see below) which may be 357545d5ecaSDag-Erling Smørgravsent without 358333ee039SDag-Erling Smørgrav.Xr sshd 8 359cf2b5f3bSDag-Erling Smørgravreceiving any messages back from the client. 360cf2b5f3bSDag-Erling SmørgravIf this threshold is reached while client alive messages are being sent, 361333ee039SDag-Erling Smørgravsshd will disconnect the client, terminating the session. 362cf2b5f3bSDag-Erling SmørgravIt is important to note that the use of client alive messages is very 363cf2b5f3bSDag-Erling Smørgravdifferent from 3641ec0d754SDag-Erling Smørgrav.Cm TCPKeepAlive 365cf2b5f3bSDag-Erling Smørgrav(below). 366cf2b5f3bSDag-Erling SmørgravThe client alive messages are sent through the encrypted channel 367cf2b5f3bSDag-Erling Smørgravand therefore will not be spoofable. 368cf2b5f3bSDag-Erling SmørgravThe TCP keepalive option enabled by 3691ec0d754SDag-Erling Smørgrav.Cm TCPKeepAlive 370cf2b5f3bSDag-Erling Smørgravis spoofable. 371cf2b5f3bSDag-Erling SmørgravThe client alive mechanism is valuable when the client or 372545d5ecaSDag-Erling Smørgravserver depend on knowing when a connection has become inactive. 373545d5ecaSDag-Erling Smørgrav.Pp 374cf2b5f3bSDag-Erling SmørgravThe default value is 3. 375cf2b5f3bSDag-Erling SmørgravIf 376545d5ecaSDag-Erling Smørgrav.Cm ClientAliveInterval 377b74df5b2SDag-Erling Smørgrav(see below) is set to 15, and 378545d5ecaSDag-Erling Smørgrav.Cm ClientAliveCountMax 379333ee039SDag-Erling Smørgravis left at the default, unresponsive SSH clients 380545d5ecaSDag-Erling Smørgravwill be disconnected after approximately 45 seconds. 381333ee039SDag-Erling SmørgravThis option applies to protocol version 2 only. 382d4ecd108SDag-Erling Smørgrav.It Cm ClientAliveInterval 383d4ecd108SDag-Erling SmørgravSets a timeout interval in seconds after which if no data has been received 384d4ecd108SDag-Erling Smørgravfrom the client, 385333ee039SDag-Erling Smørgrav.Xr sshd 8 386d4ecd108SDag-Erling Smørgravwill send a message through the encrypted 387d4ecd108SDag-Erling Smørgravchannel to request a response from the client. 388d4ecd108SDag-Erling SmørgravThe default 389d4ecd108SDag-Erling Smørgravis 0, indicating that these messages will not be sent to the client. 390d4ecd108SDag-Erling SmørgravThis option applies to protocol version 2 only. 391545d5ecaSDag-Erling Smørgrav.It Cm Compression 392d4ecd108SDag-Erling SmørgravSpecifies whether compression is allowed, or delayed until 393d4ecd108SDag-Erling Smørgravthe user has authenticated successfully. 394545d5ecaSDag-Erling SmørgravThe argument must be 395d4ecd108SDag-Erling Smørgrav.Dq yes , 396d4ecd108SDag-Erling Smørgrav.Dq delayed , 397545d5ecaSDag-Erling Smørgravor 398545d5ecaSDag-Erling Smørgrav.Dq no . 399545d5ecaSDag-Erling SmørgravThe default is 400d4ecd108SDag-Erling Smørgrav.Dq delayed . 401545d5ecaSDag-Erling Smørgrav.It Cm DenyGroups 402545d5ecaSDag-Erling SmørgravThis keyword can be followed by a list of group name patterns, separated 403545d5ecaSDag-Erling Smørgravby spaces. 404545d5ecaSDag-Erling SmørgravLogin is disallowed for users whose primary group or supplementary 405545d5ecaSDag-Erling Smørgravgroup list matches one of the patterns. 406545d5ecaSDag-Erling SmørgravOnly group names are valid; a numerical group ID is not recognized. 407545d5ecaSDag-Erling SmørgravBy default, login is allowed for all groups. 408333ee039SDag-Erling SmørgravThe allow/deny directives are processed in the following order: 409333ee039SDag-Erling Smørgrav.Cm DenyUsers , 410333ee039SDag-Erling Smørgrav.Cm AllowUsers , 411333ee039SDag-Erling Smørgrav.Cm DenyGroups , 412333ee039SDag-Erling Smørgravand finally 413333ee039SDag-Erling Smørgrav.Cm AllowGroups . 414333ee039SDag-Erling Smørgrav.Pp 415333ee039SDag-Erling SmørgravSee 416333ee039SDag-Erling Smørgrav.Sx PATTERNS 417333ee039SDag-Erling Smørgravin 418333ee039SDag-Erling Smørgrav.Xr ssh_config 5 419333ee039SDag-Erling Smørgravfor more information on patterns. 420545d5ecaSDag-Erling Smørgrav.It Cm DenyUsers 421545d5ecaSDag-Erling SmørgravThis keyword can be followed by a list of user name patterns, separated 422545d5ecaSDag-Erling Smørgravby spaces. 423545d5ecaSDag-Erling SmørgravLogin is disallowed for user names that match one of the patterns. 424545d5ecaSDag-Erling SmørgravOnly user names are valid; a numerical user ID is not recognized. 425545d5ecaSDag-Erling SmørgravBy default, login is allowed for all users. 426545d5ecaSDag-Erling SmørgravIf the pattern takes the form USER@HOST then USER and HOST 427545d5ecaSDag-Erling Smørgravare separately checked, restricting logins to particular 428545d5ecaSDag-Erling Smørgravusers from particular hosts. 429333ee039SDag-Erling SmørgravThe allow/deny directives are processed in the following order: 430333ee039SDag-Erling Smørgrav.Cm DenyUsers , 431333ee039SDag-Erling Smørgrav.Cm AllowUsers , 432333ee039SDag-Erling Smørgrav.Cm DenyGroups , 433333ee039SDag-Erling Smørgravand finally 434333ee039SDag-Erling Smørgrav.Cm AllowGroups . 435333ee039SDag-Erling Smørgrav.Pp 436333ee039SDag-Erling SmørgravSee 437333ee039SDag-Erling Smørgrav.Sx PATTERNS 438333ee039SDag-Erling Smørgravin 439333ee039SDag-Erling Smørgrav.Xr ssh_config 5 440333ee039SDag-Erling Smørgravfor more information on patterns. 441333ee039SDag-Erling Smørgrav.It Cm ForceCommand 442333ee039SDag-Erling SmørgravForces the execution of the command specified by 443333ee039SDag-Erling Smørgrav.Cm ForceCommand , 444d4af9e69SDag-Erling Smørgravignoring any command supplied by the client and 445d4af9e69SDag-Erling Smørgrav.Pa ~/.ssh/rc 446d4af9e69SDag-Erling Smørgravif present. 447333ee039SDag-Erling SmørgravThe command is invoked by using the user's login shell with the -c option. 448333ee039SDag-Erling SmørgravThis applies to shell, command, or subsystem execution. 449333ee039SDag-Erling SmørgravIt is most useful inside a 450333ee039SDag-Erling Smørgrav.Cm Match 451333ee039SDag-Erling Smørgravblock. 452333ee039SDag-Erling SmørgravThe command originally supplied by the client is available in the 453333ee039SDag-Erling Smørgrav.Ev SSH_ORIGINAL_COMMAND 454333ee039SDag-Erling Smørgravenvironment variable. 455d4af9e69SDag-Erling SmørgravSpecifying a command of 456d4af9e69SDag-Erling Smørgrav.Dq internal-sftp 457d4af9e69SDag-Erling Smørgravwill force the use of an in-process sftp server that requires no support 458d4af9e69SDag-Erling Smørgravfiles when used with 459d4af9e69SDag-Erling Smørgrav.Cm ChrootDirectory . 460545d5ecaSDag-Erling Smørgrav.It Cm GatewayPorts 461545d5ecaSDag-Erling SmørgravSpecifies whether remote hosts are allowed to connect to ports 462545d5ecaSDag-Erling Smørgravforwarded for the client. 463545d5ecaSDag-Erling SmørgravBy default, 464333ee039SDag-Erling Smørgrav.Xr sshd 8 465e73e9afaSDag-Erling Smørgravbinds remote port forwardings to the loopback address. 466e73e9afaSDag-Erling SmørgravThis prevents other remote hosts from connecting to forwarded ports. 467545d5ecaSDag-Erling Smørgrav.Cm GatewayPorts 468333ee039SDag-Erling Smørgravcan be used to specify that sshd 469aa49c926SDag-Erling Smørgravshould allow remote port forwardings to bind to non-loopback addresses, thus 470aa49c926SDag-Erling Smørgravallowing other hosts to connect. 471aa49c926SDag-Erling SmørgravThe argument may be 472aa49c926SDag-Erling Smørgrav.Dq no 473aa49c926SDag-Erling Smørgravto force remote port forwardings to be available to the local host only, 474545d5ecaSDag-Erling Smørgrav.Dq yes 475aa49c926SDag-Erling Smørgravto force remote port forwardings to bind to the wildcard address, or 476aa49c926SDag-Erling Smørgrav.Dq clientspecified 477aa49c926SDag-Erling Smørgravto allow the client to select the address to which the forwarding is bound. 478545d5ecaSDag-Erling SmørgravThe default is 479545d5ecaSDag-Erling Smørgrav.Dq no . 480cf2b5f3bSDag-Erling Smørgrav.It Cm GSSAPIAuthentication 481cf2b5f3bSDag-Erling SmørgravSpecifies whether user authentication based on GSSAPI is allowed. 482cf2b5f3bSDag-Erling SmørgravThe default is 483cf2b5f3bSDag-Erling Smørgrav.Dq no . 484cf2b5f3bSDag-Erling SmørgravNote that this option applies to protocol version 2 only. 485cf2b5f3bSDag-Erling Smørgrav.It Cm GSSAPICleanupCredentials 486cf2b5f3bSDag-Erling SmørgravSpecifies whether to automatically destroy the user's credentials cache 487cf2b5f3bSDag-Erling Smørgravon logout. 488cf2b5f3bSDag-Erling SmørgravThe default is 489cf2b5f3bSDag-Erling Smørgrav.Dq yes . 490cf2b5f3bSDag-Erling SmørgravNote that this option applies to protocol version 2 only. 491545d5ecaSDag-Erling Smørgrav.It Cm HostbasedAuthentication 492545d5ecaSDag-Erling SmørgravSpecifies whether rhosts or /etc/hosts.equiv authentication together 493545d5ecaSDag-Erling Smørgravwith successful public key client host authentication is allowed 494333ee039SDag-Erling Smørgrav(host-based authentication). 495545d5ecaSDag-Erling SmørgravThis option is similar to 496545d5ecaSDag-Erling Smørgrav.Cm RhostsRSAAuthentication 497545d5ecaSDag-Erling Smørgravand applies to protocol version 2 only. 498545d5ecaSDag-Erling SmørgravThe default is 499545d5ecaSDag-Erling Smørgrav.Dq no . 500333ee039SDag-Erling Smørgrav.It Cm HostbasedUsesNameFromPacketOnly 501333ee039SDag-Erling SmørgravSpecifies whether or not the server will attempt to perform a reverse 502333ee039SDag-Erling Smørgravname lookup when matching the name in the 503333ee039SDag-Erling Smørgrav.Pa ~/.shosts , 504333ee039SDag-Erling Smørgrav.Pa ~/.rhosts , 505333ee039SDag-Erling Smørgravand 506333ee039SDag-Erling Smørgrav.Pa /etc/hosts.equiv 507333ee039SDag-Erling Smørgravfiles during 508333ee039SDag-Erling Smørgrav.Cm HostbasedAuthentication . 509333ee039SDag-Erling SmørgravA setting of 510333ee039SDag-Erling Smørgrav.Dq yes 511333ee039SDag-Erling Smørgravmeans that 512333ee039SDag-Erling Smørgrav.Xr sshd 8 513333ee039SDag-Erling Smørgravuses the name supplied by the client rather than 514333ee039SDag-Erling Smørgravattempting to resolve the name from the TCP connection itself. 515333ee039SDag-Erling SmørgravThe default is 516333ee039SDag-Erling Smørgrav.Dq no . 517b15c8340SDag-Erling Smørgrav.It Cm HostCertificate 518b15c8340SDag-Erling SmørgravSpecifies a file containing a public host certificate. 519b15c8340SDag-Erling SmørgravThe certificate's public key must match a private host key already specified 520b15c8340SDag-Erling Smørgravby 521b15c8340SDag-Erling Smørgrav.Cm HostKey . 522b15c8340SDag-Erling SmørgravThe default behaviour of 523b15c8340SDag-Erling Smørgrav.Xr sshd 8 524b15c8340SDag-Erling Smørgravis not to load any certificates. 525545d5ecaSDag-Erling Smørgrav.It Cm HostKey 526545d5ecaSDag-Erling SmørgravSpecifies a file containing a private host key 527545d5ecaSDag-Erling Smørgravused by SSH. 528545d5ecaSDag-Erling SmørgravThe default is 529545d5ecaSDag-Erling Smørgrav.Pa /etc/ssh/ssh_host_key 530545d5ecaSDag-Erling Smørgravfor protocol version 1, and 5314a421b63SDag-Erling Smørgrav.Pa /etc/ssh/ssh_host_dsa_key , 5324a421b63SDag-Erling Smørgrav.Pa /etc/ssh/ssh_host_ecdsa_key 533d4af9e69SDag-Erling Smørgravand 5344a421b63SDag-Erling Smørgrav.Pa /etc/ssh/ssh_host_rsa_key 535545d5ecaSDag-Erling Smørgravfor protocol version 2. 536545d5ecaSDag-Erling SmørgravNote that 537333ee039SDag-Erling Smørgrav.Xr sshd 8 538545d5ecaSDag-Erling Smørgravwill refuse to use a file if it is group/world-accessible. 539545d5ecaSDag-Erling SmørgravIt is possible to have multiple host key files. 540545d5ecaSDag-Erling Smørgrav.Dq rsa1 541545d5ecaSDag-Erling Smørgravkeys are used for version 1 and 5424a421b63SDag-Erling Smørgrav.Dq dsa , 5434a421b63SDag-Erling Smørgrav.Dq ecdsa 544545d5ecaSDag-Erling Smørgravor 545545d5ecaSDag-Erling Smørgrav.Dq rsa 546545d5ecaSDag-Erling Smørgravare used for version 2 of the SSH protocol. 547545d5ecaSDag-Erling Smørgrav.It Cm IgnoreRhosts 548545d5ecaSDag-Erling SmørgravSpecifies that 549545d5ecaSDag-Erling Smørgrav.Pa .rhosts 550545d5ecaSDag-Erling Smørgravand 551545d5ecaSDag-Erling Smørgrav.Pa .shosts 552545d5ecaSDag-Erling Smørgravfiles will not be used in 553545d5ecaSDag-Erling Smørgrav.Cm RhostsRSAAuthentication 554545d5ecaSDag-Erling Smørgravor 555545d5ecaSDag-Erling Smørgrav.Cm HostbasedAuthentication . 556545d5ecaSDag-Erling Smørgrav.Pp 557545d5ecaSDag-Erling Smørgrav.Pa /etc/hosts.equiv 558545d5ecaSDag-Erling Smørgravand 55935d4ccfbSDag-Erling Smørgrav.Pa /etc/ssh/shosts.equiv 560545d5ecaSDag-Erling Smørgravare still used. 561545d5ecaSDag-Erling SmørgravThe default is 562545d5ecaSDag-Erling Smørgrav.Dq yes . 563545d5ecaSDag-Erling Smørgrav.It Cm IgnoreUserKnownHosts 564545d5ecaSDag-Erling SmørgravSpecifies whether 565333ee039SDag-Erling Smørgrav.Xr sshd 8 566545d5ecaSDag-Erling Smørgravshould ignore the user's 567d4ecd108SDag-Erling Smørgrav.Pa ~/.ssh/known_hosts 568545d5ecaSDag-Erling Smørgravduring 569545d5ecaSDag-Erling Smørgrav.Cm RhostsRSAAuthentication 570545d5ecaSDag-Erling Smørgravor 571545d5ecaSDag-Erling Smørgrav.Cm HostbasedAuthentication . 572545d5ecaSDag-Erling SmørgravThe default is 573545d5ecaSDag-Erling Smørgrav.Dq no . 5744a421b63SDag-Erling Smørgrav.It Cm IPQoS 5754a421b63SDag-Erling SmørgravSpecifies the IPv4 type-of-service or DSCP class for the connection. 5764a421b63SDag-Erling SmørgravAccepted values are 5774a421b63SDag-Erling Smørgrav.Dq af11 , 5784a421b63SDag-Erling Smørgrav.Dq af12 , 5794a421b63SDag-Erling Smørgrav.Dq af13 , 580462c32cbSDag-Erling Smørgrav.Dq af21 , 5814a421b63SDag-Erling Smørgrav.Dq af22 , 5824a421b63SDag-Erling Smørgrav.Dq af23 , 5834a421b63SDag-Erling Smørgrav.Dq af31 , 5844a421b63SDag-Erling Smørgrav.Dq af32 , 5854a421b63SDag-Erling Smørgrav.Dq af33 , 5864a421b63SDag-Erling Smørgrav.Dq af41 , 5874a421b63SDag-Erling Smørgrav.Dq af42 , 5884a421b63SDag-Erling Smørgrav.Dq af43 , 5894a421b63SDag-Erling Smørgrav.Dq cs0 , 5904a421b63SDag-Erling Smørgrav.Dq cs1 , 5914a421b63SDag-Erling Smørgrav.Dq cs2 , 5924a421b63SDag-Erling Smørgrav.Dq cs3 , 5934a421b63SDag-Erling Smørgrav.Dq cs4 , 5944a421b63SDag-Erling Smørgrav.Dq cs5 , 5954a421b63SDag-Erling Smørgrav.Dq cs6 , 5964a421b63SDag-Erling Smørgrav.Dq cs7 , 5974a421b63SDag-Erling Smørgrav.Dq ef , 5984a421b63SDag-Erling Smørgrav.Dq lowdelay , 5994a421b63SDag-Erling Smørgrav.Dq throughput , 6004a421b63SDag-Erling Smørgrav.Dq reliability , 6014a421b63SDag-Erling Smørgravor a numeric value. 6024a421b63SDag-Erling SmørgravThis option may take one or two arguments, separated by whitespace. 6034a421b63SDag-Erling SmørgravIf one argument is specified, it is used as the packet class unconditionally. 6044a421b63SDag-Erling SmørgravIf two values are specified, the first is automatically selected for 6054a421b63SDag-Erling Smørgravinteractive sessions and the second for non-interactive sessions. 6064a421b63SDag-Erling SmørgravThe default is 6074a421b63SDag-Erling Smørgrav.Dq lowdelay 6084a421b63SDag-Erling Smørgravfor interactive sessions and 6094a421b63SDag-Erling Smørgrav.Dq throughput 6104a421b63SDag-Erling Smørgravfor non-interactive sessions. 611545d5ecaSDag-Erling Smørgrav.It Cm KerberosAuthentication 612cf2b5f3bSDag-Erling SmørgravSpecifies whether the password provided by the user for 613545d5ecaSDag-Erling Smørgrav.Cm PasswordAuthentication 614cf2b5f3bSDag-Erling Smørgravwill be validated through the Kerberos KDC. 615545d5ecaSDag-Erling SmørgravTo use this option, the server needs a 616545d5ecaSDag-Erling SmørgravKerberos servtab which allows the verification of the KDC's identity. 617333ee039SDag-Erling SmørgravThe default is 618545d5ecaSDag-Erling Smørgrav.Dq no . 6195962c0e9SDag-Erling Smørgrav.It Cm KerberosGetAFSToken 620b74df5b2SDag-Erling SmørgravIf AFS is active and the user has a Kerberos 5 TGT, attempt to acquire 6215962c0e9SDag-Erling Smørgravan AFS token before accessing the user's home directory. 622333ee039SDag-Erling SmørgravThe default is 6235962c0e9SDag-Erling Smørgrav.Dq no . 624545d5ecaSDag-Erling Smørgrav.It Cm KerberosOrLocalPasswd 625333ee039SDag-Erling SmørgravIf password authentication through Kerberos fails then 626545d5ecaSDag-Erling Smørgravthe password will be validated via any additional local mechanism 627545d5ecaSDag-Erling Smørgravsuch as 628545d5ecaSDag-Erling Smørgrav.Pa /etc/passwd . 629333ee039SDag-Erling SmørgravThe default is 630545d5ecaSDag-Erling Smørgrav.Dq yes . 631545d5ecaSDag-Erling Smørgrav.It Cm KerberosTicketCleanup 632545d5ecaSDag-Erling SmørgravSpecifies whether to automatically destroy the user's ticket cache 633545d5ecaSDag-Erling Smørgravfile on logout. 634333ee039SDag-Erling SmørgravThe default is 635545d5ecaSDag-Erling Smørgrav.Dq yes . 6364a421b63SDag-Erling Smørgrav.It Cm KexAlgorithms 6374a421b63SDag-Erling SmørgravSpecifies the available KEX (Key Exchange) algorithms. 6384a421b63SDag-Erling SmørgravMultiple algorithms must be comma-separated. 6394a421b63SDag-Erling SmørgravThe default is 6404a421b63SDag-Erling Smørgrav.Dq ecdh-sha2-nistp256 , 6414a421b63SDag-Erling Smørgrav.Dq ecdh-sha2-nistp384 , 6424a421b63SDag-Erling Smørgrav.Dq ecdh-sha2-nistp521 , 6434a421b63SDag-Erling Smørgrav.Dq diffie-hellman-group-exchange-sha256 , 6444a421b63SDag-Erling Smørgrav.Dq diffie-hellman-group-exchange-sha1 , 6454a421b63SDag-Erling Smørgrav.Dq diffie-hellman-group14-sha1 , 6464a421b63SDag-Erling Smørgrav.Dq diffie-hellman-group1-sha1 . 647545d5ecaSDag-Erling Smørgrav.It Cm KeyRegenerationInterval 648545d5ecaSDag-Erling SmørgravIn protocol version 1, the ephemeral server key is automatically regenerated 649545d5ecaSDag-Erling Smørgravafter this many seconds (if it has been used). 650545d5ecaSDag-Erling SmørgravThe purpose of regeneration is to prevent 651545d5ecaSDag-Erling Smørgravdecrypting captured sessions by later breaking into the machine and 652545d5ecaSDag-Erling Smørgravstealing the keys. 653545d5ecaSDag-Erling SmørgravThe key is never stored anywhere. 654545d5ecaSDag-Erling SmørgravIf the value is 0, the key is never regenerated. 655545d5ecaSDag-Erling SmørgravThe default is 3600 (seconds). 656545d5ecaSDag-Erling Smørgrav.It Cm ListenAddress 657545d5ecaSDag-Erling SmørgravSpecifies the local addresses 658333ee039SDag-Erling Smørgrav.Xr sshd 8 659545d5ecaSDag-Erling Smørgravshould listen on. 660545d5ecaSDag-Erling SmørgravThe following forms may be used: 661545d5ecaSDag-Erling Smørgrav.Pp 662545d5ecaSDag-Erling Smørgrav.Bl -item -offset indent -compact 663545d5ecaSDag-Erling Smørgrav.It 664545d5ecaSDag-Erling Smørgrav.Cm ListenAddress 665545d5ecaSDag-Erling Smørgrav.Sm off 666545d5ecaSDag-Erling Smørgrav.Ar host No | Ar IPv4_addr No | Ar IPv6_addr 667545d5ecaSDag-Erling Smørgrav.Sm on 668545d5ecaSDag-Erling Smørgrav.It 669545d5ecaSDag-Erling Smørgrav.Cm ListenAddress 670545d5ecaSDag-Erling Smørgrav.Sm off 671545d5ecaSDag-Erling Smørgrav.Ar host No | Ar IPv4_addr No : Ar port 672545d5ecaSDag-Erling Smørgrav.Sm on 673545d5ecaSDag-Erling Smørgrav.It 674545d5ecaSDag-Erling Smørgrav.Cm ListenAddress 675545d5ecaSDag-Erling Smørgrav.Sm off 676545d5ecaSDag-Erling Smørgrav.Oo 677545d5ecaSDag-Erling Smørgrav.Ar host No | Ar IPv6_addr Oc : Ar port 678545d5ecaSDag-Erling Smørgrav.Sm on 679545d5ecaSDag-Erling Smørgrav.El 680545d5ecaSDag-Erling Smørgrav.Pp 681545d5ecaSDag-Erling SmørgravIf 682545d5ecaSDag-Erling Smørgrav.Ar port 683545d5ecaSDag-Erling Smørgravis not specified, 684333ee039SDag-Erling Smørgravsshd will listen on the address and all prior 685545d5ecaSDag-Erling Smørgrav.Cm Port 686cf2b5f3bSDag-Erling Smørgravoptions specified. 687cf2b5f3bSDag-Erling SmørgravThe default is to listen on all local addresses. 688e73e9afaSDag-Erling SmørgravMultiple 689545d5ecaSDag-Erling Smørgrav.Cm ListenAddress 690cf2b5f3bSDag-Erling Smørgravoptions are permitted. 691cf2b5f3bSDag-Erling SmørgravAdditionally, any 692545d5ecaSDag-Erling Smørgrav.Cm Port 693333ee039SDag-Erling Smørgravoptions must precede this option for non-port qualified addresses. 694545d5ecaSDag-Erling Smørgrav.It Cm LoginGraceTime 695545d5ecaSDag-Erling SmørgravThe server disconnects after this time if the user has not 696545d5ecaSDag-Erling Smørgravsuccessfully logged in. 697545d5ecaSDag-Erling SmørgravIf the value is 0, there is no time limit. 698f388f5efSDag-Erling SmørgravThe default is 120 seconds. 699545d5ecaSDag-Erling Smørgrav.It Cm LogLevel 700545d5ecaSDag-Erling SmørgravGives the verbosity level that is used when logging messages from 701333ee039SDag-Erling Smørgrav.Xr sshd 8 . 702545d5ecaSDag-Erling SmørgravThe possible values are: 703333ee039SDag-Erling SmørgravQUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3. 704e73e9afaSDag-Erling SmørgravThe default is INFO. 705e73e9afaSDag-Erling SmørgravDEBUG and DEBUG1 are equivalent. 706e73e9afaSDag-Erling SmørgravDEBUG2 and DEBUG3 each specify higher levels of debugging output. 707e73e9afaSDag-Erling SmørgravLogging with a DEBUG level violates the privacy of users and is not recommended. 708545d5ecaSDag-Erling Smørgrav.It Cm MACs 709545d5ecaSDag-Erling SmørgravSpecifies the available MAC (message authentication code) algorithms. 710545d5ecaSDag-Erling SmørgravThe MAC algorithm is used in protocol version 2 711545d5ecaSDag-Erling Smørgravfor data integrity protection. 712545d5ecaSDag-Erling SmørgravMultiple algorithms must be comma-separated. 7136888a9beSDag-Erling SmørgravThe algorithms that contain 7146888a9beSDag-Erling Smørgrav.Dq -etm 7156888a9beSDag-Erling Smørgravcalculate the MAC after encryption (encrypt-then-mac). 7166888a9beSDag-Erling SmørgravThese are considered safer and their use recommended. 717333ee039SDag-Erling SmørgravThe default is: 718d4af9e69SDag-Erling Smørgrav.Bd -literal -offset indent 7196888a9beSDag-Erling Smørgravhmac-md5-etm@openssh.com,hmac-sha1-etm@openssh.com, 7206888a9beSDag-Erling Smørgravumac-64-etm@openssh.com,umac-128-etm@openssh.com, 7216888a9beSDag-Erling Smørgravhmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com, 7226888a9beSDag-Erling Smørgravhmac-ripemd160-etm@openssh.com,hmac-sha1-96-etm@openssh.com, 7236888a9beSDag-Erling Smørgravhmac-md5-96-etm@openssh.com, 7246888a9beSDag-Erling Smørgravhmac-md5,hmac-sha1,umac-64@openssh.com,umac-128@openssh.com, 725462c32cbSDag-Erling Smørgravhmac-sha2-256,hmac-sha2-512,hmac-ripemd160, 726462c32cbSDag-Erling Smørgravhmac-sha1-96,hmac-md5-96 727d4af9e69SDag-Erling Smørgrav.Ed 728333ee039SDag-Erling Smørgrav.It Cm Match 729333ee039SDag-Erling SmørgravIntroduces a conditional block. 730333ee039SDag-Erling SmørgravIf all of the criteria on the 731333ee039SDag-Erling Smørgrav.Cm Match 732333ee039SDag-Erling Smørgravline are satisfied, the keywords on the following lines override those 733333ee039SDag-Erling Smørgravset in the global section of the config file, until either another 734333ee039SDag-Erling Smørgrav.Cm Match 735333ee039SDag-Erling Smørgravline or the end of the file. 736d4af9e69SDag-Erling Smørgrav.Pp 737333ee039SDag-Erling SmørgravThe arguments to 738333ee039SDag-Erling Smørgrav.Cm Match 739333ee039SDag-Erling Smørgravare one or more criteria-pattern pairs. 740333ee039SDag-Erling SmørgravThe available criteria are 741333ee039SDag-Erling Smørgrav.Cm User , 742333ee039SDag-Erling Smørgrav.Cm Group , 743333ee039SDag-Erling Smørgrav.Cm Host , 744462c32cbSDag-Erling Smørgrav.Cm LocalAddress , 745462c32cbSDag-Erling Smørgrav.Cm LocalPort , 746333ee039SDag-Erling Smørgravand 747333ee039SDag-Erling Smørgrav.Cm Address . 748d4af9e69SDag-Erling SmørgravThe match patterns may consist of single entries or comma-separated 749d4af9e69SDag-Erling Smørgravlists and may use the wildcard and negation operators described in the 750d4af9e69SDag-Erling Smørgrav.Sx PATTERNS 751d4af9e69SDag-Erling Smørgravsection of 752d4af9e69SDag-Erling Smørgrav.Xr ssh_config 5 . 753d4af9e69SDag-Erling Smørgrav.Pp 754d4af9e69SDag-Erling SmørgravThe patterns in an 755d4af9e69SDag-Erling Smørgrav.Cm Address 756d4af9e69SDag-Erling Smørgravcriteria may additionally contain addresses to match in CIDR 757d4af9e69SDag-Erling Smørgravaddress/masklen format, e.g.\& 758d4af9e69SDag-Erling Smørgrav.Dq 192.0.2.0/24 759d4af9e69SDag-Erling Smørgravor 760d4af9e69SDag-Erling Smørgrav.Dq 3ffe:ffff::/32 . 761d4af9e69SDag-Erling SmørgravNote that the mask length provided must be consistent with the address - 762d4af9e69SDag-Erling Smørgravit is an error to specify a mask length that is too long for the address 763d4af9e69SDag-Erling Smørgravor one with bits set in this host portion of the address. 764d4af9e69SDag-Erling SmørgravFor example, 765d4af9e69SDag-Erling Smørgrav.Dq 192.0.2.0/33 766d4af9e69SDag-Erling Smørgravand 767d4af9e69SDag-Erling Smørgrav.Dq 192.0.2.0/8 768d4af9e69SDag-Erling Smørgravrespectively. 769d4af9e69SDag-Erling Smørgrav.Pp 770333ee039SDag-Erling SmørgravOnly a subset of keywords may be used on the lines following a 771333ee039SDag-Erling Smørgrav.Cm Match 772333ee039SDag-Erling Smørgravkeyword. 773333ee039SDag-Erling SmørgravAvailable keywords are 774462c32cbSDag-Erling Smørgrav.Cm AcceptEnv , 775cce7d346SDag-Erling Smørgrav.Cm AllowAgentForwarding , 776462c32cbSDag-Erling Smørgrav.Cm AllowGroups , 777333ee039SDag-Erling Smørgrav.Cm AllowTcpForwarding , 778462c32cbSDag-Erling Smørgrav.Cm AllowUsers , 7796888a9beSDag-Erling Smørgrav.Cm AuthenticationMethods , 7806888a9beSDag-Erling Smørgrav.Cm AuthorizedKeysCommand , 7816888a9beSDag-Erling Smørgrav.Cm AuthorizedKeysCommandUser , 782e2f6069cSDag-Erling Smørgrav.Cm AuthorizedKeysFile , 783e2f6069cSDag-Erling Smørgrav.Cm AuthorizedPrincipalsFile , 784d4af9e69SDag-Erling Smørgrav.Cm Banner , 785d4af9e69SDag-Erling Smørgrav.Cm ChrootDirectory , 786462c32cbSDag-Erling Smørgrav.Cm DenyGroups , 787462c32cbSDag-Erling Smørgrav.Cm DenyUsers , 788333ee039SDag-Erling Smørgrav.Cm ForceCommand , 789333ee039SDag-Erling Smørgrav.Cm GatewayPorts , 790d4af9e69SDag-Erling Smørgrav.Cm GSSAPIAuthentication , 791d4af9e69SDag-Erling Smørgrav.Cm HostbasedAuthentication , 792e2f6069cSDag-Erling Smørgrav.Cm HostbasedUsesNameFromPacketOnly , 793d4af9e69SDag-Erling Smørgrav.Cm KbdInteractiveAuthentication , 794d4af9e69SDag-Erling Smørgrav.Cm KerberosAuthentication , 795d4af9e69SDag-Erling Smørgrav.Cm MaxAuthTries , 796d4af9e69SDag-Erling Smørgrav.Cm MaxSessions , 797d4af9e69SDag-Erling Smørgrav.Cm PasswordAuthentication , 798cce7d346SDag-Erling Smørgrav.Cm PermitEmptyPasswords , 799333ee039SDag-Erling Smørgrav.Cm PermitOpen , 800d4af9e69SDag-Erling Smørgrav.Cm PermitRootLogin , 801e2f6069cSDag-Erling Smørgrav.Cm PermitTunnel , 802b15c8340SDag-Erling Smørgrav.Cm PubkeyAuthentication , 803d4af9e69SDag-Erling Smørgrav.Cm RhostsRSAAuthentication , 804d4af9e69SDag-Erling Smørgrav.Cm RSAAuthentication , 805333ee039SDag-Erling Smørgrav.Cm X11DisplayOffset , 806cce7d346SDag-Erling Smørgrav.Cm X11Forwarding 807333ee039SDag-Erling Smørgravand 808333ee039SDag-Erling Smørgrav.Cm X11UseLocalHost . 80921e764dfSDag-Erling Smørgrav.It Cm MaxAuthTries 81021e764dfSDag-Erling SmørgravSpecifies the maximum number of authentication attempts permitted per 81121e764dfSDag-Erling Smørgravconnection. 81221e764dfSDag-Erling SmørgravOnce the number of failures reaches half this value, 81321e764dfSDag-Erling Smørgravadditional failures are logged. 81421e764dfSDag-Erling SmørgravThe default is 6. 815d4af9e69SDag-Erling Smørgrav.It Cm MaxSessions 816d4af9e69SDag-Erling SmørgravSpecifies the maximum number of open sessions permitted per network connection. 817d4af9e69SDag-Erling SmørgravThe default is 10. 818545d5ecaSDag-Erling Smørgrav.It Cm MaxStartups 819545d5ecaSDag-Erling SmørgravSpecifies the maximum number of concurrent unauthenticated connections to the 820333ee039SDag-Erling SmørgravSSH daemon. 821545d5ecaSDag-Erling SmørgravAdditional connections will be dropped until authentication succeeds or the 822545d5ecaSDag-Erling Smørgrav.Cm LoginGraceTime 823545d5ecaSDag-Erling Smørgravexpires for a connection. 8246888a9beSDag-Erling SmørgravThe default is 10:30:100. 825545d5ecaSDag-Erling Smørgrav.Pp 826545d5ecaSDag-Erling SmørgravAlternatively, random early drop can be enabled by specifying 827545d5ecaSDag-Erling Smørgravthe three colon separated values 828545d5ecaSDag-Erling Smørgrav.Dq start:rate:full 829333ee039SDag-Erling Smørgrav(e.g. "10:30:60"). 830333ee039SDag-Erling Smørgrav.Xr sshd 8 831545d5ecaSDag-Erling Smørgravwill refuse connection attempts with a probability of 832545d5ecaSDag-Erling Smørgrav.Dq rate/100 833545d5ecaSDag-Erling Smørgrav(30%) 834545d5ecaSDag-Erling Smørgravif there are currently 835545d5ecaSDag-Erling Smørgrav.Dq start 836545d5ecaSDag-Erling Smørgrav(10) 837545d5ecaSDag-Erling Smørgravunauthenticated connections. 838545d5ecaSDag-Erling SmørgravThe probability increases linearly and all connection attempts 839545d5ecaSDag-Erling Smørgravare refused if the number of unauthenticated connections reaches 840545d5ecaSDag-Erling Smørgrav.Dq full 841545d5ecaSDag-Erling Smørgrav(60). 842545d5ecaSDag-Erling Smørgrav.It Cm PasswordAuthentication 843545d5ecaSDag-Erling SmørgravSpecifies whether password authentication is allowed. 844d4af9e69SDag-Erling SmørgravSee also 845d4af9e69SDag-Erling Smørgrav.Cm UsePAM . 846545d5ecaSDag-Erling SmørgravThe default is 847d4af9e69SDag-Erling Smørgrav.Dq no . 848545d5ecaSDag-Erling Smørgrav.It Cm PermitEmptyPasswords 849545d5ecaSDag-Erling SmørgravWhen password authentication is allowed, it specifies whether the 850545d5ecaSDag-Erling Smørgravserver allows login to accounts with empty password strings. 851545d5ecaSDag-Erling SmørgravThe default is 852545d5ecaSDag-Erling Smørgrav.Dq no . 853333ee039SDag-Erling Smørgrav.It Cm PermitOpen 854333ee039SDag-Erling SmørgravSpecifies the destinations to which TCP port forwarding is permitted. 855333ee039SDag-Erling SmørgravThe forwarding specification must be one of the following forms: 856333ee039SDag-Erling Smørgrav.Pp 857333ee039SDag-Erling Smørgrav.Bl -item -offset indent -compact 858333ee039SDag-Erling Smørgrav.It 859333ee039SDag-Erling Smørgrav.Cm PermitOpen 860333ee039SDag-Erling Smørgrav.Sm off 861333ee039SDag-Erling Smørgrav.Ar host : port 862333ee039SDag-Erling Smørgrav.Sm on 863333ee039SDag-Erling Smørgrav.It 864333ee039SDag-Erling Smørgrav.Cm PermitOpen 865333ee039SDag-Erling Smørgrav.Sm off 866333ee039SDag-Erling Smørgrav.Ar IPv4_addr : port 867333ee039SDag-Erling Smørgrav.Sm on 868333ee039SDag-Erling Smørgrav.It 869333ee039SDag-Erling Smørgrav.Cm PermitOpen 870333ee039SDag-Erling Smørgrav.Sm off 871333ee039SDag-Erling Smørgrav.Ar \&[ IPv6_addr \&] : port 872333ee039SDag-Erling Smørgrav.Sm on 873333ee039SDag-Erling Smørgrav.El 874333ee039SDag-Erling Smørgrav.Pp 875333ee039SDag-Erling SmørgravMultiple forwards may be specified by separating them with whitespace. 876333ee039SDag-Erling SmørgravAn argument of 877333ee039SDag-Erling Smørgrav.Dq any 878333ee039SDag-Erling Smørgravcan be used to remove all restrictions and permit any forwarding requests. 879462c32cbSDag-Erling SmørgravAn argument of 880462c32cbSDag-Erling Smørgrav.Dq none 881462c32cbSDag-Erling Smørgravcan be used to prohibit all forwarding requests. 882333ee039SDag-Erling SmørgravBy default all port forwarding requests are permitted. 883545d5ecaSDag-Erling Smørgrav.It Cm PermitRootLogin 884545d5ecaSDag-Erling SmørgravSpecifies whether root can log in using 885545d5ecaSDag-Erling Smørgrav.Xr ssh 1 . 886545d5ecaSDag-Erling SmørgravThe argument must be 887545d5ecaSDag-Erling Smørgrav.Dq yes , 888545d5ecaSDag-Erling Smørgrav.Dq without-password , 889333ee039SDag-Erling Smørgrav.Dq forced-commands-only , 890545d5ecaSDag-Erling Smørgravor 891545d5ecaSDag-Erling Smørgrav.Dq no . 892545d5ecaSDag-Erling SmørgravThe default is 89335d4ccfbSDag-Erling Smørgrav.Dq no . 894810a15b1SDag-Erling SmørgravNote that if 895810a15b1SDag-Erling Smørgrav.Cm ChallengeResponseAuthentication 896810a15b1SDag-Erling Smørgravis 897810a15b1SDag-Erling Smørgrav.Dq yes , 898810a15b1SDag-Erling Smørgravthe root user may be allowed in with its password even if 899810a15b1SDag-Erling Smørgrav.Cm PermitRootLogin is set to 900810a15b1SDag-Erling Smørgrav.Dq without-password . 901545d5ecaSDag-Erling Smørgrav.Pp 902545d5ecaSDag-Erling SmørgravIf this option is set to 903333ee039SDag-Erling Smørgrav.Dq without-password , 904aa49c926SDag-Erling Smørgravpassword authentication is disabled for root. 905545d5ecaSDag-Erling Smørgrav.Pp 906545d5ecaSDag-Erling SmørgravIf this option is set to 907333ee039SDag-Erling Smørgrav.Dq forced-commands-only , 908545d5ecaSDag-Erling Smørgravroot login with public key authentication will be allowed, 909545d5ecaSDag-Erling Smørgravbut only if the 910545d5ecaSDag-Erling Smørgrav.Ar command 911545d5ecaSDag-Erling Smørgravoption has been specified 912545d5ecaSDag-Erling Smørgrav(which may be useful for taking remote backups even if root login is 913cf2b5f3bSDag-Erling Smørgravnormally not allowed). 914cf2b5f3bSDag-Erling SmørgravAll other authentication methods are disabled for root. 915545d5ecaSDag-Erling Smørgrav.Pp 916545d5ecaSDag-Erling SmørgravIf this option is set to 917333ee039SDag-Erling Smørgrav.Dq no , 918545d5ecaSDag-Erling Smørgravroot is not allowed to log in. 919b74df5b2SDag-Erling Smørgrav.It Cm PermitTunnel 920b74df5b2SDag-Erling SmørgravSpecifies whether 921b74df5b2SDag-Erling Smørgrav.Xr tun 4 922b74df5b2SDag-Erling Smørgravdevice forwarding is allowed. 923b74df5b2SDag-Erling SmørgravThe argument must be 924b74df5b2SDag-Erling Smørgrav.Dq yes , 925333ee039SDag-Erling Smørgrav.Dq point-to-point 926333ee039SDag-Erling Smørgrav(layer 3), 927b74df5b2SDag-Erling Smørgrav.Dq ethernet 928333ee039SDag-Erling Smørgrav(layer 2), or 929b74df5b2SDag-Erling Smørgrav.Dq no . 930333ee039SDag-Erling SmørgravSpecifying 931333ee039SDag-Erling Smørgrav.Dq yes 932333ee039SDag-Erling Smørgravpermits both 933333ee039SDag-Erling Smørgrav.Dq point-to-point 934333ee039SDag-Erling Smørgravand 935333ee039SDag-Erling Smørgrav.Dq ethernet . 936b74df5b2SDag-Erling SmørgravThe default is 937b74df5b2SDag-Erling Smørgrav.Dq no . 938f388f5efSDag-Erling Smørgrav.It Cm PermitUserEnvironment 939f388f5efSDag-Erling SmørgravSpecifies whether 940f388f5efSDag-Erling Smørgrav.Pa ~/.ssh/environment 941f388f5efSDag-Erling Smørgravand 942f388f5efSDag-Erling Smørgrav.Cm environment= 943f388f5efSDag-Erling Smørgravoptions in 944f388f5efSDag-Erling Smørgrav.Pa ~/.ssh/authorized_keys 945f388f5efSDag-Erling Smørgravare processed by 946333ee039SDag-Erling Smørgrav.Xr sshd 8 . 947f388f5efSDag-Erling SmørgravThe default is 948f388f5efSDag-Erling Smørgrav.Dq no . 949f388f5efSDag-Erling SmørgravEnabling environment processing may enable users to bypass access 950f388f5efSDag-Erling Smørgravrestrictions in some configurations using mechanisms such as 951f388f5efSDag-Erling Smørgrav.Ev LD_PRELOAD . 952545d5ecaSDag-Erling Smørgrav.It Cm PidFile 953a82e551fSDag-Erling SmørgravSpecifies the file that contains the process ID of the 954333ee039SDag-Erling SmørgravSSH daemon. 955545d5ecaSDag-Erling SmørgravThe default is 956545d5ecaSDag-Erling Smørgrav.Pa /var/run/sshd.pid . 957545d5ecaSDag-Erling Smørgrav.It Cm Port 958545d5ecaSDag-Erling SmørgravSpecifies the port number that 959333ee039SDag-Erling Smørgrav.Xr sshd 8 960545d5ecaSDag-Erling Smørgravlistens on. 961545d5ecaSDag-Erling SmørgravThe default is 22. 962545d5ecaSDag-Erling SmørgravMultiple options of this type are permitted. 963545d5ecaSDag-Erling SmørgravSee also 964545d5ecaSDag-Erling Smørgrav.Cm ListenAddress . 965545d5ecaSDag-Erling Smørgrav.It Cm PrintLastLog 966545d5ecaSDag-Erling SmørgravSpecifies whether 967333ee039SDag-Erling Smørgrav.Xr sshd 8 968aa49c926SDag-Erling Smørgravshould print the date and time of the last user login when a user logs 969aa49c926SDag-Erling Smørgravin interactively. 970545d5ecaSDag-Erling SmørgravThe default is 971545d5ecaSDag-Erling Smørgrav.Dq yes . 972545d5ecaSDag-Erling Smørgrav.It Cm PrintMotd 973545d5ecaSDag-Erling SmørgravSpecifies whether 974333ee039SDag-Erling Smørgrav.Xr sshd 8 975545d5ecaSDag-Erling Smørgravshould print 976545d5ecaSDag-Erling Smørgrav.Pa /etc/motd 977545d5ecaSDag-Erling Smørgravwhen a user logs in interactively. 978545d5ecaSDag-Erling Smørgrav(On some systems it is also printed by the shell, 979545d5ecaSDag-Erling Smørgrav.Pa /etc/profile , 980545d5ecaSDag-Erling Smørgravor equivalent.) 981545d5ecaSDag-Erling SmørgravThe default is 982545d5ecaSDag-Erling Smørgrav.Dq yes . 983545d5ecaSDag-Erling Smørgrav.It Cm Protocol 984545d5ecaSDag-Erling SmørgravSpecifies the protocol versions 985333ee039SDag-Erling Smørgrav.Xr sshd 8 986f388f5efSDag-Erling Smørgravsupports. 987545d5ecaSDag-Erling SmørgravThe possible values are 988333ee039SDag-Erling Smørgrav.Sq 1 989545d5ecaSDag-Erling Smørgravand 990333ee039SDag-Erling Smørgrav.Sq 2 . 991545d5ecaSDag-Erling SmørgravMultiple versions must be comma-separated. 992545d5ecaSDag-Erling SmørgravThe default is 993b15c8340SDag-Erling Smørgrav.Sq 2 . 994f388f5efSDag-Erling SmørgravNote that the order of the protocol list does not indicate preference, 995f388f5efSDag-Erling Smørgravbecause the client selects among multiple protocol versions offered 996f388f5efSDag-Erling Smørgravby the server. 997f388f5efSDag-Erling SmørgravSpecifying 998f388f5efSDag-Erling Smørgrav.Dq 2,1 999f388f5efSDag-Erling Smørgravis identical to 1000f388f5efSDag-Erling Smørgrav.Dq 1,2 . 1001545d5ecaSDag-Erling Smørgrav.It Cm PubkeyAuthentication 1002545d5ecaSDag-Erling SmørgravSpecifies whether public key authentication is allowed. 1003545d5ecaSDag-Erling SmørgravThe default is 1004545d5ecaSDag-Erling Smørgrav.Dq yes . 1005545d5ecaSDag-Erling SmørgravNote that this option applies to protocol version 2 only. 1006b15c8340SDag-Erling Smørgrav.It Cm RevokedKeys 10076888a9beSDag-Erling SmørgravSpecifies revoked public keys. 1008b15c8340SDag-Erling SmørgravKeys listed in this file will be refused for public key authentication. 1009b15c8340SDag-Erling SmørgravNote that if this file is not readable, then public key authentication will 1010b15c8340SDag-Erling Smørgravbe refused for all users. 10116888a9beSDag-Erling SmørgravKeys may be specified as a text file, listing one public key per line, or as 10126888a9beSDag-Erling Smørgravan OpenSSH Key Revocation List (KRL) as generated by 10136888a9beSDag-Erling Smørgrav.Xr ssh-keygen 1 . 10146888a9beSDag-Erling SmørgravFor more information on KRLs, see the 10156888a9beSDag-Erling Smørgrav.Sx KEY REVOCATION LISTS 10166888a9beSDag-Erling Smørgravsection in 10176888a9beSDag-Erling Smørgrav.Xr ssh-keygen 1 . 1018545d5ecaSDag-Erling Smørgrav.It Cm RhostsRSAAuthentication 101935d4ccfbSDag-Erling SmørgravSpecifies whether rhosts or 102035d4ccfbSDag-Erling Smørgrav.Pa /etc/hosts.equiv 102135d4ccfbSDag-Erling Smørgravauthentication together 1022545d5ecaSDag-Erling Smørgravwith successful RSA host authentication is allowed. 1023545d5ecaSDag-Erling SmørgravThe default is 1024545d5ecaSDag-Erling Smørgrav.Dq no . 1025545d5ecaSDag-Erling SmørgravThis option applies to protocol version 1 only. 1026545d5ecaSDag-Erling Smørgrav.It Cm RSAAuthentication 1027545d5ecaSDag-Erling SmørgravSpecifies whether pure RSA authentication is allowed. 1028545d5ecaSDag-Erling SmørgravThe default is 1029545d5ecaSDag-Erling Smørgrav.Dq yes . 1030545d5ecaSDag-Erling SmørgravThis option applies to protocol version 1 only. 1031545d5ecaSDag-Erling Smørgrav.It Cm ServerKeyBits 1032545d5ecaSDag-Erling SmørgravDefines the number of bits in the ephemeral protocol version 1 server key. 1033d4af9e69SDag-Erling SmørgravThe minimum value is 512, and the default is 1024. 1034545d5ecaSDag-Erling Smørgrav.It Cm StrictModes 1035545d5ecaSDag-Erling SmørgravSpecifies whether 1036333ee039SDag-Erling Smørgrav.Xr sshd 8 1037545d5ecaSDag-Erling Smørgravshould check file modes and ownership of the 1038545d5ecaSDag-Erling Smørgravuser's files and home directory before accepting login. 1039545d5ecaSDag-Erling SmørgravThis is normally desirable because novices sometimes accidentally leave their 1040545d5ecaSDag-Erling Smørgravdirectory or files world-writable. 1041545d5ecaSDag-Erling SmørgravThe default is 1042545d5ecaSDag-Erling Smørgrav.Dq yes . 1043b15c8340SDag-Erling SmørgravNote that this does not apply to 1044b15c8340SDag-Erling Smørgrav.Cm ChrootDirectory , 1045b15c8340SDag-Erling Smørgravwhose permissions and ownership are checked unconditionally. 1046545d5ecaSDag-Erling Smørgrav.It Cm Subsystem 1047333ee039SDag-Erling SmørgravConfigures an external subsystem (e.g. file transfer daemon). 1048333ee039SDag-Erling SmørgravArguments should be a subsystem name and a command (with optional arguments) 1049333ee039SDag-Erling Smørgravto execute upon subsystem request. 1050d4af9e69SDag-Erling Smørgrav.Pp 1051545d5ecaSDag-Erling SmørgravThe command 1052545d5ecaSDag-Erling Smørgrav.Xr sftp-server 8 1053545d5ecaSDag-Erling Smørgravimplements the 1054545d5ecaSDag-Erling Smørgrav.Dq sftp 1055545d5ecaSDag-Erling Smørgravfile transfer subsystem. 1056d4af9e69SDag-Erling Smørgrav.Pp 1057d4af9e69SDag-Erling SmørgravAlternately the name 1058d4af9e69SDag-Erling Smørgrav.Dq internal-sftp 1059d4af9e69SDag-Erling Smørgravimplements an in-process 1060d4af9e69SDag-Erling Smørgrav.Dq sftp 1061d4af9e69SDag-Erling Smørgravserver. 1062d4af9e69SDag-Erling SmørgravThis may simplify configurations using 1063d4af9e69SDag-Erling Smørgrav.Cm ChrootDirectory 1064d4af9e69SDag-Erling Smørgravto force a different filesystem root on clients. 1065d4af9e69SDag-Erling Smørgrav.Pp 1066545d5ecaSDag-Erling SmørgravBy default no subsystems are defined. 1067545d5ecaSDag-Erling SmørgravNote that this option applies to protocol version 2 only. 1068545d5ecaSDag-Erling Smørgrav.It Cm SyslogFacility 1069545d5ecaSDag-Erling SmørgravGives the facility code that is used when logging messages from 1070333ee039SDag-Erling Smørgrav.Xr sshd 8 . 1071545d5ecaSDag-Erling SmørgravThe possible values are: DAEMON, USER, AUTH, LOCAL0, LOCAL1, LOCAL2, 1072545d5ecaSDag-Erling SmørgravLOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7. 1073545d5ecaSDag-Erling SmørgravThe default is AUTH. 10741ec0d754SDag-Erling Smørgrav.It Cm TCPKeepAlive 10751ec0d754SDag-Erling SmørgravSpecifies whether the system should send TCP keepalive messages to the 10761ec0d754SDag-Erling Smørgravother side. 10771ec0d754SDag-Erling SmørgravIf they are sent, death of the connection or crash of one 10781ec0d754SDag-Erling Smørgravof the machines will be properly noticed. 10791ec0d754SDag-Erling SmørgravHowever, this means that 10801ec0d754SDag-Erling Smørgravconnections will die if the route is down temporarily, and some people 10811ec0d754SDag-Erling Smørgravfind it annoying. 10821ec0d754SDag-Erling SmørgravOn the other hand, if TCP keepalives are not sent, 10831ec0d754SDag-Erling Smørgravsessions may hang indefinitely on the server, leaving 10841ec0d754SDag-Erling Smørgrav.Dq ghost 10851ec0d754SDag-Erling Smørgravusers and consuming server resources. 10861ec0d754SDag-Erling Smørgrav.Pp 10871ec0d754SDag-Erling SmørgravThe default is 10881ec0d754SDag-Erling Smørgrav.Dq yes 10891ec0d754SDag-Erling Smørgrav(to send TCP keepalive messages), and the server will notice 10901ec0d754SDag-Erling Smørgravif the network goes down or the client host crashes. 10911ec0d754SDag-Erling SmørgravThis avoids infinitely hanging sessions. 10921ec0d754SDag-Erling Smørgrav.Pp 10931ec0d754SDag-Erling SmørgravTo disable TCP keepalive messages, the value should be set to 10941ec0d754SDag-Erling Smørgrav.Dq no . 1095b15c8340SDag-Erling Smørgrav.It Cm TrustedUserCAKeys 1096b15c8340SDag-Erling SmørgravSpecifies a file containing public keys of certificate authorities that are 1097b15c8340SDag-Erling Smørgravtrusted to sign user certificates for authentication. 1098b15c8340SDag-Erling SmørgravKeys are listed one per line; empty lines and comments starting with 1099b15c8340SDag-Erling Smørgrav.Ql # 1100b15c8340SDag-Erling Smørgravare allowed. 1101b15c8340SDag-Erling SmørgravIf a certificate is presented for authentication and has its signing CA key 1102b15c8340SDag-Erling Smørgravlisted in this file, then it may be used for authentication for any user 1103b15c8340SDag-Erling Smørgravlisted in the certificate's principals list. 1104b15c8340SDag-Erling SmørgravNote that certificates that lack a list of principals will not be permitted 1105b15c8340SDag-Erling Smørgravfor authentication using 1106b15c8340SDag-Erling Smørgrav.Cm TrustedUserCAKeys . 1107b15c8340SDag-Erling SmørgravFor more details on certificates, see the 1108b15c8340SDag-Erling Smørgrav.Sx CERTIFICATES 1109b15c8340SDag-Erling Smørgravsection in 1110b15c8340SDag-Erling Smørgrav.Xr ssh-keygen 1 . 1111cf2b5f3bSDag-Erling Smørgrav.It Cm UseDNS 1112cf2b5f3bSDag-Erling SmørgravSpecifies whether 1113333ee039SDag-Erling Smørgrav.Xr sshd 8 1114cf2b5f3bSDag-Erling Smørgravshould look up the remote host name and check that 1115cf2b5f3bSDag-Erling Smørgravthe resolved host name for the remote IP address maps back to the 1116cf2b5f3bSDag-Erling Smørgravvery same IP address. 1117cf2b5f3bSDag-Erling SmørgravThe default is 1118cf2b5f3bSDag-Erling Smørgrav.Dq yes . 1119545d5ecaSDag-Erling Smørgrav.It Cm UseLogin 1120545d5ecaSDag-Erling SmørgravSpecifies whether 1121545d5ecaSDag-Erling Smørgrav.Xr login 1 1122545d5ecaSDag-Erling Smørgravis used for interactive login sessions. 1123545d5ecaSDag-Erling SmørgravThe default is 1124545d5ecaSDag-Erling Smørgrav.Dq no . 1125545d5ecaSDag-Erling SmørgravNote that 1126545d5ecaSDag-Erling Smørgrav.Xr login 1 1127545d5ecaSDag-Erling Smørgravis never used for remote command execution. 1128545d5ecaSDag-Erling SmørgravNote also, that if this is enabled, 1129545d5ecaSDag-Erling Smørgrav.Cm X11Forwarding 1130545d5ecaSDag-Erling Smørgravwill be disabled because 1131545d5ecaSDag-Erling Smørgrav.Xr login 1 1132545d5ecaSDag-Erling Smørgravdoes not know how to handle 1133545d5ecaSDag-Erling Smørgrav.Xr xauth 1 1134e73e9afaSDag-Erling Smørgravcookies. 1135e73e9afaSDag-Erling SmørgravIf 1136545d5ecaSDag-Erling Smørgrav.Cm UsePrivilegeSeparation 1137545d5ecaSDag-Erling Smørgravis specified, it will be disabled after authentication. 1138cf2b5f3bSDag-Erling Smørgrav.It Cm UsePAM 113921e764dfSDag-Erling SmørgravEnables the Pluggable Authentication Module interface. 114021e764dfSDag-Erling SmørgravIf set to 114121e764dfSDag-Erling Smørgrav.Dq yes 114221e764dfSDag-Erling Smørgravthis will enable PAM authentication using 114321e764dfSDag-Erling Smørgrav.Cm ChallengeResponseAuthentication 1144333ee039SDag-Erling Smørgravand 1145333ee039SDag-Erling Smørgrav.Cm PasswordAuthentication 1146333ee039SDag-Erling Smørgravin addition to PAM account and session module processing for all 1147333ee039SDag-Erling Smørgravauthentication types. 114821e764dfSDag-Erling Smørgrav.Pp 114921e764dfSDag-Erling SmørgravBecause PAM challenge-response authentication usually serves an equivalent 115021e764dfSDag-Erling Smørgravrole to password authentication, you should disable either 115121e764dfSDag-Erling Smørgrav.Cm PasswordAuthentication 115221e764dfSDag-Erling Smørgravor 115321e764dfSDag-Erling Smørgrav.Cm ChallengeResponseAuthentication. 115421e764dfSDag-Erling Smørgrav.Pp 115521e764dfSDag-Erling SmørgravIf 115621e764dfSDag-Erling Smørgrav.Cm UsePAM 115721e764dfSDag-Erling Smørgravis enabled, you will not be able to run 115821e764dfSDag-Erling Smørgrav.Xr sshd 8 115921e764dfSDag-Erling Smørgravas a non-root user. 116021e764dfSDag-Erling SmørgravThe default is 1161d2b1b4f3SDag-Erling Smørgrav.Dq yes . 1162545d5ecaSDag-Erling Smørgrav.It Cm UsePrivilegeSeparation 1163545d5ecaSDag-Erling SmørgravSpecifies whether 1164333ee039SDag-Erling Smørgrav.Xr sshd 8 1165545d5ecaSDag-Erling Smørgravseparates privileges by creating an unprivileged child process 1166e73e9afaSDag-Erling Smørgravto deal with incoming network traffic. 1167e73e9afaSDag-Erling SmørgravAfter successful authentication, another process will be created that has 1168e73e9afaSDag-Erling Smørgravthe privilege of the authenticated user. 1169e73e9afaSDag-Erling SmørgravThe goal of privilege separation is to prevent privilege 1170545d5ecaSDag-Erling Smørgravescalation by containing any corruption within the unprivileged processes. 1171545d5ecaSDag-Erling SmørgravThe default is 1172*aa0dd44bSDag-Erling Smørgrav.Dq yes . 1173e146993eSDag-Erling SmørgravIf 1174e146993eSDag-Erling Smørgrav.Cm UsePrivilegeSeparation 1175e146993eSDag-Erling Smørgravis set to 1176e146993eSDag-Erling Smørgrav.Dq sandbox 1177e146993eSDag-Erling Smørgravthen the pre-authentication unprivileged process is subject to additional 1178e146993eSDag-Erling Smørgravrestrictions. 117935d4ccfbSDag-Erling Smørgrav.It Cm VersionAddendum 1180462c32cbSDag-Erling SmørgravOptionally specifies additional text to append to the SSH protocol banner 1181462c32cbSDag-Erling Smørgravsent by the server upon connection. 1182ee8aeb14SDag-Erling SmørgravThe default is 1183420bce64SDag-Erling Smørgrav.Dq FreeBSD-20130515 . 1184545d5ecaSDag-Erling Smørgrav.It Cm X11DisplayOffset 1185545d5ecaSDag-Erling SmørgravSpecifies the first display number available for 1186333ee039SDag-Erling Smørgrav.Xr sshd 8 Ns 's 1187545d5ecaSDag-Erling SmørgravX11 forwarding. 1188333ee039SDag-Erling SmørgravThis prevents sshd from interfering with real X11 servers. 1189545d5ecaSDag-Erling SmørgravThe default is 10. 1190545d5ecaSDag-Erling Smørgrav.It Cm X11Forwarding 1191545d5ecaSDag-Erling SmørgravSpecifies whether X11 forwarding is permitted. 1192f388f5efSDag-Erling SmørgravThe argument must be 1193f388f5efSDag-Erling Smørgrav.Dq yes 1194f388f5efSDag-Erling Smørgravor 1195f388f5efSDag-Erling Smørgrav.Dq no . 1196545d5ecaSDag-Erling SmørgravThe default is 1197ee8aeb14SDag-Erling Smørgrav.Dq yes . 1198f388f5efSDag-Erling Smørgrav.Pp 1199f388f5efSDag-Erling SmørgravWhen X11 forwarding is enabled, there may be additional exposure to 1200f388f5efSDag-Erling Smørgravthe server and to client displays if the 1201333ee039SDag-Erling Smørgrav.Xr sshd 8 1202f388f5efSDag-Erling Smørgravproxy display is configured to listen on the wildcard address (see 1203f388f5efSDag-Erling Smørgrav.Cm X11UseLocalhost 1204333ee039SDag-Erling Smørgravbelow), though this is not the default. 1205f388f5efSDag-Erling SmørgravAdditionally, the authentication spoofing and authentication data 1206f388f5efSDag-Erling Smørgravverification and substitution occur on the client side. 1207f388f5efSDag-Erling SmørgravThe security risk of using X11 forwarding is that the client's X11 1208333ee039SDag-Erling Smørgravdisplay server may be exposed to attack when the SSH client requests 1209f388f5efSDag-Erling Smørgravforwarding (see the warnings for 1210f388f5efSDag-Erling Smørgrav.Cm ForwardX11 1211f388f5efSDag-Erling Smørgravin 1212f388f5efSDag-Erling Smørgrav.Xr ssh_config 5 ) . 1213f388f5efSDag-Erling SmørgravA system administrator may have a stance in which they want to 1214f388f5efSDag-Erling Smørgravprotect clients that may expose themselves to attack by unwittingly 1215f388f5efSDag-Erling Smørgravrequesting X11 forwarding, which can warrant a 1216f388f5efSDag-Erling Smørgrav.Dq no 1217f388f5efSDag-Erling Smørgravsetting. 1218f388f5efSDag-Erling Smørgrav.Pp 1219f388f5efSDag-Erling SmørgravNote that disabling X11 forwarding does not prevent users from 1220f388f5efSDag-Erling Smørgravforwarding X11 traffic, as users can always install their own forwarders. 1221545d5ecaSDag-Erling SmørgravX11 forwarding is automatically disabled if 1222545d5ecaSDag-Erling Smørgrav.Cm UseLogin 1223545d5ecaSDag-Erling Smørgravis enabled. 1224545d5ecaSDag-Erling Smørgrav.It Cm X11UseLocalhost 1225545d5ecaSDag-Erling SmørgravSpecifies whether 1226333ee039SDag-Erling Smørgrav.Xr sshd 8 1227545d5ecaSDag-Erling Smørgravshould bind the X11 forwarding server to the loopback address or to 1228e73e9afaSDag-Erling Smørgravthe wildcard address. 1229e73e9afaSDag-Erling SmørgravBy default, 1230333ee039SDag-Erling Smørgravsshd binds the forwarding server to the loopback address and sets the 1231545d5ecaSDag-Erling Smørgravhostname part of the 1232545d5ecaSDag-Erling Smørgrav.Ev DISPLAY 1233545d5ecaSDag-Erling Smørgravenvironment variable to 1234545d5ecaSDag-Erling Smørgrav.Dq localhost . 1235f388f5efSDag-Erling SmørgravThis prevents remote hosts from connecting to the proxy display. 1236545d5ecaSDag-Erling SmørgravHowever, some older X11 clients may not function with this 1237545d5ecaSDag-Erling Smørgravconfiguration. 1238545d5ecaSDag-Erling Smørgrav.Cm X11UseLocalhost 1239545d5ecaSDag-Erling Smørgravmay be set to 1240545d5ecaSDag-Erling Smørgrav.Dq no 1241545d5ecaSDag-Erling Smørgravto specify that the forwarding server should be bound to the wildcard 1242545d5ecaSDag-Erling Smørgravaddress. 1243545d5ecaSDag-Erling SmørgravThe argument must be 1244545d5ecaSDag-Erling Smørgrav.Dq yes 1245545d5ecaSDag-Erling Smørgravor 1246545d5ecaSDag-Erling Smørgrav.Dq no . 1247545d5ecaSDag-Erling SmørgravThe default is 1248545d5ecaSDag-Erling Smørgrav.Dq yes . 1249545d5ecaSDag-Erling Smørgrav.It Cm XAuthLocation 1250f388f5efSDag-Erling SmørgravSpecifies the full pathname of the 1251545d5ecaSDag-Erling Smørgrav.Xr xauth 1 1252545d5ecaSDag-Erling Smørgravprogram. 1253545d5ecaSDag-Erling SmørgravThe default is 1254ffea3f5aSDag-Erling Smørgrav.Pa /usr/local/bin/xauth . 1255545d5ecaSDag-Erling Smørgrav.El 1256333ee039SDag-Erling Smørgrav.Sh TIME FORMATS 1257333ee039SDag-Erling Smørgrav.Xr sshd 8 1258545d5ecaSDag-Erling Smørgravcommand-line arguments and configuration file options that specify time 1259545d5ecaSDag-Erling Smørgravmay be expressed using a sequence of the form: 1260545d5ecaSDag-Erling Smørgrav.Sm off 1261f388f5efSDag-Erling Smørgrav.Ar time Op Ar qualifier , 1262545d5ecaSDag-Erling Smørgrav.Sm on 1263545d5ecaSDag-Erling Smørgravwhere 1264545d5ecaSDag-Erling Smørgrav.Ar time 1265545d5ecaSDag-Erling Smørgravis a positive integer value and 1266545d5ecaSDag-Erling Smørgrav.Ar qualifier 1267545d5ecaSDag-Erling Smørgravis one of the following: 1268545d5ecaSDag-Erling Smørgrav.Pp 1269545d5ecaSDag-Erling Smørgrav.Bl -tag -width Ds -compact -offset indent 1270333ee039SDag-Erling Smørgrav.It Aq Cm none 1271545d5ecaSDag-Erling Smørgravseconds 1272545d5ecaSDag-Erling Smørgrav.It Cm s | Cm S 1273545d5ecaSDag-Erling Smørgravseconds 1274545d5ecaSDag-Erling Smørgrav.It Cm m | Cm M 1275545d5ecaSDag-Erling Smørgravminutes 1276545d5ecaSDag-Erling Smørgrav.It Cm h | Cm H 1277545d5ecaSDag-Erling Smørgravhours 1278545d5ecaSDag-Erling Smørgrav.It Cm d | Cm D 1279545d5ecaSDag-Erling Smørgravdays 1280545d5ecaSDag-Erling Smørgrav.It Cm w | Cm W 1281545d5ecaSDag-Erling Smørgravweeks 1282545d5ecaSDag-Erling Smørgrav.El 1283545d5ecaSDag-Erling Smørgrav.Pp 1284545d5ecaSDag-Erling SmørgravEach member of the sequence is added together to calculate 1285545d5ecaSDag-Erling Smørgravthe total time value. 1286545d5ecaSDag-Erling Smørgrav.Pp 1287545d5ecaSDag-Erling SmørgravTime format examples: 1288545d5ecaSDag-Erling Smørgrav.Pp 1289545d5ecaSDag-Erling Smørgrav.Bl -tag -width Ds -compact -offset indent 1290545d5ecaSDag-Erling Smørgrav.It 600 1291545d5ecaSDag-Erling Smørgrav600 seconds (10 minutes) 1292545d5ecaSDag-Erling Smørgrav.It 10m 1293545d5ecaSDag-Erling Smørgrav10 minutes 1294545d5ecaSDag-Erling Smørgrav.It 1h30m 1295545d5ecaSDag-Erling Smørgrav1 hour 30 minutes (90 minutes) 1296545d5ecaSDag-Erling Smørgrav.El 1297545d5ecaSDag-Erling Smørgrav.Sh FILES 1298545d5ecaSDag-Erling Smørgrav.Bl -tag -width Ds 1299545d5ecaSDag-Erling Smørgrav.It Pa /etc/ssh/sshd_config 1300545d5ecaSDag-Erling SmørgravContains configuration data for 1301333ee039SDag-Erling Smørgrav.Xr sshd 8 . 1302545d5ecaSDag-Erling SmørgravThis file should be writable by root only, but it is recommended 1303545d5ecaSDag-Erling Smørgrav(though not necessary) that it be world-readable. 1304545d5ecaSDag-Erling Smørgrav.El 1305cf2b5f3bSDag-Erling Smørgrav.Sh SEE ALSO 1306cf2b5f3bSDag-Erling Smørgrav.Xr sshd 8 1307545d5ecaSDag-Erling Smørgrav.Sh AUTHORS 1308545d5ecaSDag-Erling SmørgravOpenSSH is a derivative of the original and free 1309545d5ecaSDag-Erling Smørgravssh 1.2.12 release by Tatu Ylonen. 1310545d5ecaSDag-Erling SmørgravAaron Campbell, Bob Beck, Markus Friedl, Niels Provos, 1311545d5ecaSDag-Erling SmørgravTheo de Raadt and Dug Song 1312545d5ecaSDag-Erling Smørgravremoved many bugs, re-added newer features and 1313545d5ecaSDag-Erling Smørgravcreated OpenSSH. 1314545d5ecaSDag-Erling SmørgravMarkus Friedl contributed the support for SSH 1315545d5ecaSDag-Erling Smørgravprotocol versions 1.5 and 2.0. 1316545d5ecaSDag-Erling SmørgravNiels Provos and Markus Friedl contributed support 1317545d5ecaSDag-Erling Smørgravfor privilege separation. 1318