Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 1 | # $OpenBSD: sshd_config,v 1.44 2002/01/16 17:40:23 stevesk Exp $ |
Tim Rice | 59ea0a0 | 2001-03-10 13:50:45 -0800 | [diff] [blame] | 2 | |
Damien Miller | 3380426 | 2001-02-04 23:20:18 +1100 | [diff] [blame] | 3 | # This is the sshd server system-wide configuration file. See sshd(8) |
| 4 | # for more information. |
Damien Miller | d4a8b7e | 1999-10-27 13:42:43 +1000 | [diff] [blame] | 5 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 6 | # The stategy used for options in the default sshd_config shipped with |
| 7 | # OpenSSH is to specify options with their default value where |
| 8 | # possible, but leave them commented. Uncommented options change a |
| 9 | # default value. |
| 10 | |
| 11 | #Port 22 |
Damien Miller | 8bb73be | 2000-04-19 16:26:12 +1000 | [diff] [blame] | 12 | #Protocol 2,1 |
Kevin Steves | 8ee4f69 | 2001-01-09 15:28:46 +0000 | [diff] [blame] | 13 | #ListenAddress 0.0.0.0 |
Damien Miller | 34132e5 | 2000-01-14 15:45:46 +1100 | [diff] [blame] | 14 | #ListenAddress :: |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 15 | |
| 16 | # HostKey for protocol version 1 |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 17 | #HostKey /etc/ssh_host_key |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 18 | # HostKeys for protocol version 2 |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 19 | #HostKey /etc/ssh_host_rsa_key |
| 20 | #HostKey /etc/ssh_host_dsa_key |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 21 | |
| 22 | # Lifetime and size of ephemeral version 1 server key |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 23 | #KeyRegenerationInterval 3600 |
| 24 | #ServerKeyBits 768 |
Damien Miller | 192bd01 | 1999-11-13 23:56:35 +1100 | [diff] [blame] | 25 | |
Damien Miller | 886c63a | 2000-01-20 23:13:36 +1100 | [diff] [blame] | 26 | # Logging |
Damien Miller | 886c63a | 2000-01-20 23:13:36 +1100 | [diff] [blame] | 27 | #obsoletes QuietMode and FascistLogging |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 28 | #SyslogFacility AUTH |
| 29 | #LogLevel INFO |
Damien Miller | 9ba3024 | 1999-11-11 21:07:00 +1100 | [diff] [blame] | 30 | |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 31 | # Authentication: |
| 32 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 33 | #LoginGraceTime 600 |
| 34 | #PermitRootLogin yes |
| 35 | #StrictModes yes |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 36 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 37 | #RSAAuthentication yes |
| 38 | #PubkeyAuthentication yes |
| 39 | #AuthorizedKeysFile .ssh/authorized_keys |
Damien Miller | d4a8b7e | 1999-10-27 13:42:43 +1000 | [diff] [blame] | 40 | |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 41 | # rhosts authentication should not be used |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 42 | #RhostsAuthentication no |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 43 | # Don't read the user's ~/.rhosts and ~/.shosts files |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 44 | #IgnoreRhosts yes |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 45 | # For this to work you will also need host keys in /etc/ssh_known_hosts |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 46 | #RhostsRSAAuthentication no |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 47 | # similar for protocol version 2 |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 48 | #HostbasedAuthentication no |
| 49 | # Change to yes if you don't trust ~/.ssh/known_hosts for |
| 50 | # RhostsRSAAuthentication and HostbasedAuthentication |
| 51 | #IgnoreUserKnownHosts no |
Ben Lindstrom | c4b7225 | 2001-06-09 01:09:51 +0000 | [diff] [blame] | 52 | |
Damien Miller | d4a8b7e | 1999-10-27 13:42:43 +1000 | [diff] [blame] | 53 | # To disable tunneled clear text passwords, change to no here! |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 54 | #PasswordAuthentication yes |
| 55 | #PermitEmptyPasswords no |
Damien Miller | 3380426 | 2001-02-04 23:20:18 +1100 | [diff] [blame] | 56 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 57 | # Change to no to disable s/key passwords |
| 58 | #ChallengeResponseAuthentication yes |
Damien Miller | f815442 | 2001-04-25 22:44:14 +1000 | [diff] [blame] | 59 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 60 | # Kerberos options |
| 61 | # KerberosAuthentication automatically enabled if keyfile exists |
| 62 | #KerberosAuthentication yes |
| 63 | #KerberosOrLocalPasswd yes |
| 64 | #KerberosTicketCleanup yes |
| 65 | |
| 66 | # AFSTokenPassing automatically enabled if k_hasafs() is true |
| 67 | #AFSTokenPassing yes |
| 68 | |
| 69 | # Kerberos TGT Passing only works with the AFS kaserver |
| 70 | #KerberosTgtPassing no |
| 71 | |
| 72 | # Set this to 'yes' to enable PAM keyboard-interactive authentication |
Damien Miller | f815442 | 2001-04-25 22:44:14 +1000 | [diff] [blame] | 73 | # Warning: enabling this may bypass the setting of 'PasswordAuthentication' |
| 74 | #PAMAuthenticationViaKbdInt yes |
Damien Miller | d4a8b7e | 1999-10-27 13:42:43 +1000 | [diff] [blame] | 75 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 76 | #X11Forwarding no |
| 77 | #X11DisplayOffset 10 |
| 78 | #PrintMotd yes |
| 79 | #PrintLastLog yes |
| 80 | #KeepAlive yes |
Damien Miller | c30d35c | 2000-08-30 09:40:09 +1100 | [diff] [blame] | 81 | #UseLogin no |
Damien Miller | f6d9e22 | 2000-06-18 14:50:44 +1000 | [diff] [blame] | 82 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 83 | #MaxStartups 10 |
| 84 | # no default banner path |
| 85 | #Banner /some/path |
| 86 | #ReverseMappingCheck no |
Ben Lindstrom | e9d0444 | 2001-02-10 23:26:35 +0000 | [diff] [blame] | 87 | |
Damien Miller | 2bec5c1 | 2002-01-22 23:32:07 +1100 | [diff] [blame^] | 88 | # override default of no subsystems |
Ben Lindstrom | e9d0444 | 2001-02-10 23:26:35 +0000 | [diff] [blame] | 89 | Subsystem sftp /usr/libexec/sftp-server |