mirror of
git://anongit.mindrot.org/openssh.git
synced 2024-12-27 12:22:09 +00:00
34132e54cb
- [sshd.c sshd.8 sshconnect.c ssh.h ssh.c servconf.h servconf.c scp.1] [scp.c packet.h packet.c login.c log.c canohost.c channels.c] [hostfile.c sshd_config] ipv6 support: mostly gethostbyname->getaddrinfo/getnameinfo, new features: sshd allows multiple ListenAddress and Port options. note that libwrap is not IPv6-ready. (based on patches from fujiwara@rcac.tdi.co.jp) - [ssh.c canohost.c] more hints (hints.ai_socktype=SOCK_STREAM) for getaddrinfo, from itojun@ - [channels.c] listen on _all_ interfaces for X11-Fwd (hints.ai_flags = AI_PASSIVE) - [packet.h] allow auth-kerberos for IPv4 only - [scp.1 sshd.8 servconf.h scp.c] document -4, -6, and 'ssh -L 2022/::1/22' - [ssh.c] 'ssh @host' is illegal (null user name), from karsten@gedankenpolizei.de - [sshconnect.c] better error message - [sshd.c] allow auth-kerberos for IPv4 only - Big IPv6 merge: - Cleanup overrun in sockaddr copying on RHL 6.1 - Replacements for getaddrinfo, getnameinfo, etc based on versions from patch from KIKUCHI Takahiro <kick@kyoto.wide.ad.jp> - Replacement for missing structures on systems that lack IPv6 - record_login needed to know about AF_INET6 addresses - Borrowed more code from OpenBSD: rresvport_af and requisites
61 lines
1.2 KiB
Plaintext
61 lines
1.2 KiB
Plaintext
# This is ssh server systemwide configuration file.
|
|
|
|
Port 22
|
|
ListenAddress 0.0.0.0
|
|
#ListenAddress ::
|
|
HostKey @sysconfdir@/ssh_host_key
|
|
ServerKeyBits 768
|
|
LoginGraceTime 600
|
|
KeyRegenerationInterval 3600
|
|
PermitRootLogin yes
|
|
StrictModes yes
|
|
X11Forwarding no
|
|
X11DisplayOffset 10
|
|
PrintMotd yes
|
|
KeepAlive yes
|
|
CheckMail no
|
|
UseLogin no
|
|
|
|
#
|
|
# Loglevel replaces QuietMode and FascistLogging
|
|
#
|
|
SyslogFacility AUTH
|
|
LogLevel INFO
|
|
|
|
#
|
|
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
|
|
#
|
|
RhostsRSAAuthentication no
|
|
|
|
#
|
|
# Don't read ~/.rhosts and ~/.shosts files
|
|
#
|
|
IgnoreRhosts yes
|
|
RhostsAuthentication no
|
|
|
|
#
|
|
# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
|
|
#
|
|
#IgnoreUserKnownHosts yes
|
|
|
|
RSAAuthentication yes
|
|
|
|
# To disable tunneled clear text passwords, change to no here!
|
|
PasswordAuthentication yes
|
|
PermitEmptyPasswords no
|
|
|
|
#
|
|
# Uncomment to disable s/key passwords (must be compiled with s/key support)
|
|
#
|
|
#SkeyAuthentication no
|
|
|
|
#
|
|
# To change Kerberos options (must be compiled with Kerberos support)
|
|
#
|
|
#KerberosAuthentication no
|
|
#KerberosOrLocalPasswd yes
|
|
#AFSTokenPassing no
|
|
#KerberosTicketCleanup no
|
|
# Kerberos TGT Passing does only work with the AFS kaserver
|
|
#KerberosTgtPassing yes
|