summaryrefslogtreecommitdiff
path: root/sshd_config.5
diff options
context:
space:
mode:
authorDamien Miller <djm@mindrot.org>2013-04-23 15:23:07 +1000
committerDamien Miller <djm@mindrot.org>2013-04-23 15:23:07 +1000
commit467b00c38ba244f9966466e57a89d003f3afb159 (patch)
treec41d37fd16a887692419a663790a744207f8efd8 /sshd_config.5
parent9303e6527bb5ca7630c765f28624702c212bfd6c (diff)
- djm@cvs.openbsd.org 2013/04/19 01:00:10
[sshd_config.5] document the requirment that the AuthorizedKeysCommand be owned by root; ok dtucker@ markus@
Diffstat (limited to 'sshd_config.5')
-rw-r--r--sshd_config.57
1 files changed, 4 insertions, 3 deletions
diff --git a/sshd_config.5 b/sshd_config.5
index 4fe3c55b6..590fb4088 100644
--- a/sshd_config.5
+++ b/sshd_config.5
@@ -33,8 +33,8 @@
33.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 33.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
34.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 34.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
35.\" 35.\"
36.\" $OpenBSD: sshd_config.5,v 1.157 2013/03/07 19:27:25 markus Exp $ 36.\" $OpenBSD: sshd_config.5,v 1.158 2013/04/19 01:00:10 djm Exp $
37.Dd $Mdocdate: March 7 2013 $ 37.Dd $Mdocdate: April 19 2013 $
38.Dt SSHD_CONFIG 5 38.Dt SSHD_CONFIG 5
39.Os 39.Os
40.Sh NAME 40.Sh NAME
@@ -202,7 +202,8 @@ The default is not to require multiple authentication; successful completion
202of a single authentication method is sufficient. 202of a single authentication method is sufficient.
203.It Cm AuthorizedKeysCommand 203.It Cm AuthorizedKeysCommand
204Specifies a program to be used to look up the user's public keys. 204Specifies a program to be used to look up the user's public keys.
205The program will be invoked with a single argument of the username 205The program must be owned by root and not writable by group or others.
206It will be invoked with a single argument of the username
206being authenticated, and should produce on standard output zero or 207being authenticated, and should produce on standard output zero or
207more lines of authorized_keys output (see 208more lines of authorized_keys output (see
208.Sx AUTHORIZED_KEYS 209.Sx AUTHORIZED_KEYS