summaryrefslogtreecommitdiff
path: root/sftp-server.0
diff options
context:
space:
mode:
authorColin Watson <cjwatson@debian.org>2010-03-31 10:46:28 +0100
committerColin Watson <cjwatson@debian.org>2010-03-31 10:46:28 +0100
commitefd3d4522636ae029488c2e9730b60c88e257d2e (patch)
tree31e02ac3f16090ce8c53448677356b2b7f423683 /sftp-server.0
parentbbec4db36d464ea1d464a707625125f9fd5c7b5e (diff)
parentd1a87e462e1db89f19cd960588d0c6b287cb5ccc (diff)
* New upstream release (LP: #535029).
- After a transition period of about 10 years, this release disables SSH protocol 1 by default. Clients and servers that need to use the legacy protocol must explicitly enable it in ssh_config / sshd_config or on the command-line. - Remove the libsectok/OpenSC-based smartcard code and add support for PKCS#11 tokens. This support is enabled by default in the Debian packaging, since it now doesn't involve additional library dependencies (closes: #231472, LP: #16918). - Add support for certificate authentication of users and hosts using a new, minimal OpenSSH certificate format (closes: #482806). - Added a 'netcat mode' to ssh(1): "ssh -W host:port ...". - Add the ability to revoke keys in sshd(8) and ssh(1). (For the Debian package, this overlaps with the key blacklisting facility added in openssh 1:4.7p1-9, but with different file formats and slightly different scopes; for the moment, I've roughly merged the two.) - Various multiplexing improvements, including support for requesting port-forwardings via the multiplex protocol (closes: #360151). - Allow setting an explicit umask on the sftp-server(8) commandline to override whatever default the user has (closes: #496843). - Many sftp client improvements, including tab-completion, more options, and recursive transfer support for get/put (LP: #33378). The old mget/mput commands never worked properly and have been removed (closes: #270399, #428082). - Do not prompt for a passphrase if we fail to open a keyfile, and log the reason why the open failed to debug (closes: #431538). - Prevent sftp from crashing when given a "-" without a command. Also, allow whitespace to follow a "-" (closes: #531561).
Diffstat (limited to 'sftp-server.0')
-rw-r--r--sftp-server.017
1 files changed, 15 insertions, 2 deletions
diff --git a/sftp-server.0 b/sftp-server.0
index d47fc0ceb..6628dcfca 100644
--- a/sftp-server.0
+++ b/sftp-server.0
@@ -4,7 +4,7 @@ NAME
4 sftp-server - SFTP server subsystem 4 sftp-server - SFTP server subsystem
5 5
6SYNOPSIS 6SYNOPSIS
7 sftp-server [-f log_facility] [-l log_level] 7 sftp-server [-ehR] [-f log_facility] [-l log_level] [-u umask]
8 8
9DESCRIPTION 9DESCRIPTION
10 sftp-server is a program that speaks the server side of SFTP protocol to 10 sftp-server is a program that speaks the server side of SFTP protocol to
@@ -17,12 +17,17 @@ DESCRIPTION
17 17
18 Valid options are: 18 Valid options are:
19 19
20 -e Causes sftp-server to print logging information to stderr instead
21 of syslog for debugging.
22
20 -f log_facility 23 -f log_facility
21 Specifies the facility code that is used when logging messages 24 Specifies the facility code that is used when logging messages
22 from sftp-server. The possible values are: DAEMON, USER, AUTH, 25 from sftp-server. The possible values are: DAEMON, USER, AUTH,
23 LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7. 26 LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7.
24 The default is AUTH. 27 The default is AUTH.
25 28
29 -h Displays sftp-server usage information.
30
26 -l log_level 31 -l log_level
27 Specifies which messages will be logged by sftp-server. The pos- 32 Specifies which messages will be logged by sftp-server. The pos-
28 sible values are: QUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DE- 33 sible values are: QUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DE-
@@ -31,6 +36,14 @@ DESCRIPTION
31 are equivalent. DEBUG2 and DEBUG3 each specify higher levels of 36 are equivalent. DEBUG2 and DEBUG3 each specify higher levels of
32 debugging output. The default is ERROR. 37 debugging output. The default is ERROR.
33 38
39 -R Places this instance of sftp-server into a read-only mode. At-
40 tempts to open files for writing, as well as other operations
41 that change the state of the filesystem, will be denied.
42
43 -u umask
44 Sets an explicit umask(2) to be applied to newly-created files
45 and directories, instead of the user's default mask.
46
34 For logging to work, sftp-server must be able to access /dev/log. Use of 47 For logging to work, sftp-server must be able to access /dev/log. Use of
35 sftp-server in a chroot configuration therefore requires that syslogd(8) 48 sftp-server in a chroot configuration therefore requires that syslogd(8)
36 establish a logging socket inside the chroot directory. 49 establish a logging socket inside the chroot directory.
@@ -47,4 +60,4 @@ HISTORY
47AUTHORS 60AUTHORS
48 Markus Friedl <markus@openbsd.org> 61 Markus Friedl <markus@openbsd.org>
49 62
50OpenBSD 4.6 March 26, 2009 1 63OpenBSD 4.6 January 9, 2010 1