summaryrefslogtreecommitdiff
path: root/ssh-agent.1
diff options
context:
space:
mode:
authordjm@openbsd.org <djm@openbsd.org>2016-11-30 03:07:37 +0000
committerDamien Miller <djm@mindrot.org>2016-11-30 19:44:24 +1100
commit786d5994da79151180cb14a6cf157ebbba61c0cc (patch)
tree706aea69bf1507b0dca261fbc15739b2f24587a8 /ssh-agent.1
parent7844f357cdd90530eec81340847783f1f1da010b (diff)
upstream commit
add a whitelist of paths from which ssh-agent will load (via ssh-pkcs11-helper) a PKCS#11 module; ok markus@ Upstream-ID: fe79769469d9cd6d26fe0dc15751b83ef2a06e8f
Diffstat (limited to 'ssh-agent.1')
-rw-r--r--ssh-agent.117
1 files changed, 15 insertions, 2 deletions
diff --git a/ssh-agent.1 b/ssh-agent.1
index c4b50bbdf..372adbe7c 100644
--- a/ssh-agent.1
+++ b/ssh-agent.1
@@ -1,4 +1,4 @@
1.\" $OpenBSD: ssh-agent.1,v 1.62 2015/11/15 23:54:15 jmc Exp $ 1.\" $OpenBSD: ssh-agent.1,v 1.63 2016/11/30 03:07:37 djm Exp $
2.\" 2.\"
3.\" Author: Tatu Ylonen <ylo@cs.hut.fi> 3.\" Author: Tatu Ylonen <ylo@cs.hut.fi>
4.\" Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland 4.\" Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -34,7 +34,7 @@
34.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 34.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
35.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 35.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
36.\" 36.\"
37.Dd $Mdocdate: November 15 2015 $ 37.Dd $Mdocdate: November 30 2016 $
38.Dt SSH-AGENT 1 38.Dt SSH-AGENT 1
39.Os 39.Os
40.Sh NAME 40.Sh NAME
@@ -47,6 +47,7 @@
47.Op Fl a Ar bind_address 47.Op Fl a Ar bind_address
48.Op Fl E Ar fingerprint_hash 48.Op Fl E Ar fingerprint_hash
49.Op Fl t Ar life 49.Op Fl t Ar life
50.Op Fl P Ar pkcs11_whitelist
50.Op Ar command Op Ar arg ... 51.Op Ar command Op Ar arg ...
51.Nm ssh-agent 52.Nm ssh-agent
52.Op Fl c | s 53.Op Fl c | s
@@ -121,6 +122,18 @@ The default is
121Kill the current agent (given by the 122Kill the current agent (given by the
122.Ev SSH_AGENT_PID 123.Ev SSH_AGENT_PID
123environment variable). 124environment variable).
125.It Fl P
126Specify a pattern-list of acceptable paths for PKCS#11 shared libraries
127that may be added using the
128.Fl s
129option to
130.Xr ssh-add 1 .
131The default is to allow loading PKCS#11 libraries from
132.Dq /usr/lib/*,/usr/local/lib/* .
133PKCS#11 libraries that do not match the whitelist will be refused.
134See PATTERNS in
135.Xr ssh_config 5
136for a description of pattern-list syntax.
124.It Fl s 137.It Fl s
125Generate Bourne shell commands on 138Generate Bourne shell commands on
126.Dv stdout . 139.Dv stdout .