1f5cfca3e6
with openssh tree to ease future upgrade. re-do local changes, including: - prototype pedants - IgnoreRootRhosts - login.conf user validation some of the local changes that weren't used are omitted for now. we may need to revisit those afterwards. it adds "sftp".
66 lines
1.5 KiB
Plaintext
66 lines
1.5 KiB
Plaintext
# $NetBSD: sshd_config,v 1.2 2001/02/07 17:05:35 itojun Exp $
|
|
# $OpenBSD: sshd_config,v 1.32 2001/02/06 22:07:50 deraadt Exp $
|
|
|
|
# This is the sshd server system-wide configuration file. See sshd(8)
|
|
# for more information.
|
|
|
|
Port 22
|
|
#Protocol 2,1
|
|
#ListenAddress 0.0.0.0
|
|
#ListenAddress ::
|
|
HostKey /etc/ssh_host_key
|
|
HostKey /etc/ssh_host_dsa_key
|
|
#HostKey /etc/ssh_host_rsa_key
|
|
ServerKeyBits 768
|
|
LoginGraceTime 600
|
|
KeyRegenerationInterval 3600
|
|
PermitRootLogin yes
|
|
#
|
|
# Don't read ~/.rhosts and ~/.shosts files
|
|
IgnoreRhosts yes
|
|
IgnoreRootRhosts yes
|
|
# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
|
|
#IgnoreUserKnownHosts yes
|
|
StrictModes yes
|
|
X11Forwarding no
|
|
X11DisplayOffset 10
|
|
PrintMotd yes
|
|
KeepAlive yes
|
|
|
|
# Logging
|
|
SyslogFacility AUTH
|
|
LogLevel INFO
|
|
#obsoletes QuietMode and FascistLogging
|
|
|
|
RhostsAuthentication no
|
|
#
|
|
# For this to work you will also need host keys in /etc/ssh_known_hosts
|
|
RhostsRSAAuthentication no
|
|
#
|
|
RSAAuthentication yes
|
|
|
|
# To disable tunneled clear text passwords, change to no here!
|
|
PasswordAuthentication yes
|
|
PermitEmptyPasswords no
|
|
|
|
# Uncomment to disable s/key passwords
|
|
#ChallengeResponseAuthentication no
|
|
|
|
# To change Kerberos options
|
|
#KerberosAuthentication no
|
|
#KerberosOrLocalPasswd yes
|
|
#AFSTokenPassing no
|
|
#KerberosTicketCleanup no
|
|
|
|
# Kerberos TGT Passing does only work with the AFS kaserver
|
|
#KerberosTgtPassing yes
|
|
|
|
#CheckMail yes
|
|
#UseLogin no
|
|
|
|
#MaxStartups 10:30:60
|
|
#Banner /etc/issue.net
|
|
#ReverseMappingCheck yes
|
|
|
|
Subsystem sftp /usr/libexec/sftp-server
|