[BACK]Return to sshd_config CVS log [TXT][DIR] Up to [cvs.NetBSD.org] / src / crypto / dist / ssh

Please note that diffs are not public domain; they are subject to the copyright notices on the relevant files.

Diff for /src/crypto/dist/ssh/Attic/sshd_config between version 1.1.1.4 and 1.1.1.18

version 1.1.1.4, 2001/05/15 15:02:40 version 1.1.1.18, 2009/02/16 17:14:50
Line 1 
Line 1 
 #       $NetBSD$  #       $OpenBSD: sshd_config,v 1.80 2008/07/02 02:24:18 djm Exp $
 #       $OpenBSD: sshd_config,v 1.38 2001/04/15 21:41:29 deraadt Exp $  
   
 # This is the sshd server system-wide configuration file.  See sshd(8)  # This is the sshd server system-wide configuration file.  See
 # for more information.  # sshd_config(5) for more information.
   
 Port 22  # The strategy used for options in the default sshd_config shipped with
 #Protocol 2,1  # OpenSSH is to specify options with their default value where
   # possible, but leave them commented.  Uncommented options change a
   # default value.
   
   #Port 22
   #AddressFamily any
 #ListenAddress 0.0.0.0  #ListenAddress 0.0.0.0
 #ListenAddress ::  #ListenAddress ::
 HostKey /etc/ssh_host_key  
 HostKey /etc/ssh_host_rsa_key  # Disable legacy (protocol version 1) support in the server for new
 HostKey /etc/ssh_host_dsa_key  # installations. In future the default will change to require explicit
 ServerKeyBits 768  # activation of protocol 1
 LoginGraceTime 600  Protocol 2
 KeyRegenerationInterval 3600  
 PermitRootLogin yes  # HostKey for protocol version 1
 #  #HostKey /etc/ssh/ssh_host_key
 # Don't read ~/.rhosts and ~/.shosts files  # HostKeys for protocol version 2
 IgnoreRhosts yes  #HostKey /etc/ssh/ssh_host_rsa_key
 # Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication  #HostKey /etc/ssh/ssh_host_dsa_key
 #IgnoreUserKnownHosts yes  
 StrictModes yes  # Lifetime and size of ephemeral version 1 server key
 X11Forwarding no  #KeyRegenerationInterval 1h
 X11DisplayOffset 10  #ServerKeyBits 1024
 PrintMotd yes  
 #PrintLastLog no  
 KeepAlive yes  
   
 # Logging  # Logging
 SyslogFacility AUTH  # obsoletes QuietMode and FascistLogging
 LogLevel INFO  #SyslogFacility AUTH
 #obsoletes QuietMode and FascistLogging  #LogLevel INFO
   
 RhostsAuthentication no  # Authentication:
 #  
 # For this to work you will also need host keys in /etc/ssh_known_hosts  #LoginGraceTime 2m
 RhostsRSAAuthentication no  #PermitRootLogin yes
   #StrictModes yes
   #MaxAuthTries 6
   #MaxSessions 10
   
   #RSAAuthentication yes
   #PubkeyAuthentication yes
   #AuthorizedKeysFile     .ssh/authorized_keys
   
   # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
   #RhostsRSAAuthentication no
 # similar for protocol version 2  # similar for protocol version 2
 HostbasedAuthentication no  #HostbasedAuthentication no
 #  # Change to yes if you don't trust ~/.ssh/known_hosts for
 RSAAuthentication yes  # RhostsRSAAuthentication and HostbasedAuthentication
   #IgnoreUserKnownHosts no
   # Don't read the user's ~/.rhosts and ~/.shosts files
   #IgnoreRhosts yes
   
 # To disable tunneled clear text passwords, change to no here!  # To disable tunneled clear text passwords, change to no here!
 PasswordAuthentication yes  #PasswordAuthentication yes
 PermitEmptyPasswords no  #PermitEmptyPasswords no
   
 # Uncomment to disable s/key passwords  # Change to no to disable s/key passwords
 #ChallengeResponseAuthentication no  #ChallengeResponseAuthentication yes
   
 # To change Kerberos options  # Kerberos options
 #KerberosAuthentication no  #KerberosAuthentication no
 #KerberosOrLocalPasswd yes  #KerberosOrLocalPasswd yes
 #AFSTokenPassing no  #KerberosTicketCleanup yes
 #KerberosTicketCleanup no  #KerberosGetAFSToken no
   
 # Kerberos TGT Passing does only work with the AFS kaserver  # GSSAPI options
 #KerberosTgtPassing yes  #GSSAPIAuthentication no
   #GSSAPICleanupCredentials yes
 #CheckMail yes  
   #AllowAgentForwarding yes
   #AllowTcpForwarding yes
   #GatewayPorts no
   #X11Forwarding no
   #X11DisplayOffset 10
   #X11UseLocalhost yes
   #PrintMotd yes
   #PrintLastLog yes
   #TCPKeepAlive yes
 #UseLogin no  #UseLogin no
   #UsePrivilegeSeparation yes
   #PermitUserEnvironment no
   #Compression delayed
   #ClientAliveInterval 0
   #ClientAliveCountMax 3
   #UseDNS yes
   #PidFile /var/run/sshd.pid
   #MaxStartups 10
   #PermitTunnel no
   #ChrootDirectory none
   
 #MaxStartups 10:30:60  # no default banner path
 #Banner /etc/issue.net  #Banner none
 #ReverseMappingCheck yes  
   
   # override default of no subsystems
 Subsystem       sftp    /usr/libexec/sftp-server  Subsystem       sftp    /usr/libexec/sftp-server
   
   # Example of overriding settings on a per-user basis
   #Match User anoncvs
   #       X11Forwarding no
   #       AllowTcpForwarding no
   #       ForceCommand cvs server

Legend:
Removed from v.1.1.1.4  
changed lines
  Added in v.1.1.1.18

CVSweb <webmaster@jp.NetBSD.org>