summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorColin Watson <cjwatson@debian.org>2014-02-09 16:10:13 +0000
committerColin Watson <cjwatson@debian.org>2016-03-10 13:01:05 +0000
commit3e0e43c3840d4df2e44435a41981fd1eef5030b4 (patch)
treeeb9a987eda2733c79c90a34200a994b351ece32a
parentd0f5716ccb267efa3178ee03c2fc5a45d024c465 (diff)
Document consequences of ssh-agent being setgid in ssh-agent(1)
Bug-Debian: http://bugs.debian.org/711623 Forwarded: no Last-Update: 2013-06-08 Patch-Name: ssh-agent-setgid.patch
-rw-r--r--ssh-agent.115
1 files changed, 15 insertions, 0 deletions
diff --git a/ssh-agent.1 b/ssh-agent.1
index c4b50bbdf..2fe22013a 100644
--- a/ssh-agent.1
+++ b/ssh-agent.1
@@ -193,6 +193,21 @@ environment variable holds the agent's process ID.
193.Pp 193.Pp
194The agent exits automatically when the command given on the command 194The agent exits automatically when the command given on the command
195line terminates. 195line terminates.
196.Pp
197In Debian,
198.Nm
199is installed with the set-group-id bit set, to prevent
200.Xr ptrace 2
201attacks retrieving private key material.
202This has the side-effect of causing the run-time linker to remove certain
203environment variables which might have security implications for set-id
204programs, including
205.Ev LD_PRELOAD ,
206.Ev LD_LIBRARY_PATH ,
207and
208.Ev TMPDIR .
209If you need to set any of these environment variables, you will need to do
210so in the program executed by ssh-agent.
196.Sh FILES 211.Sh FILES
197.Bl -tag -width Ds 212.Bl -tag -width Ds
198.It Pa $TMPDIR/ssh-XXXXXXXXXX/agent.\*(Ltppid\*(Gt 213.It Pa $TMPDIR/ssh-XXXXXXXXXX/agent.\*(Ltppid\*(Gt