diff options
author | Simon Wilkinson <simon@sxw.org.uk> | 2014-02-09 16:09:48 +0000 |
---|---|---|
committer | Colin Watson <cjwatson@debian.org> | 2016-02-29 12:31:33 +0000 |
commit | 374db1757fc18bd6647539b80977e6907a2cecd4 (patch) | |
tree | 9fd8227bdf3548c6fcce1e72b7edf3ebaf71d050 /sshd_config.5 | |
parent | c52a95cc4754e6630c96fe65ae0c65eb41d2c590 (diff) |
GSSAPI key exchange support
This patch has been rejected upstream: "None of the OpenSSH developers are
in favour of adding this, and this situation has not changed for several
years. This is not a slight on Simon's patch, which is of fine quality, but
just that a) we don't trust GSSAPI implementations that much and b) we don't
like adding new KEX since they are pre-auth attack surface. This one is
particularly scary, since it requires hooks out to typically root-owned
system resources."
However, quite a lot of people rely on this in Debian, and it's better to
have it merged into the main openssh package rather than having separate
-krb5 packages (as we used to have). It seems to have a generally good
security history.
Bug: https://bugzilla.mindrot.org/show_bug.cgi?id=1242
Last-Updated: 2016-01-04
Patch-Name: gssapi.patch
Diffstat (limited to 'sshd_config.5')
-rw-r--r-- | sshd_config.5 | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/sshd_config.5 b/sshd_config.5 index a37a3aca3..c6d6858f9 100644 --- a/sshd_config.5 +++ b/sshd_config.5 | |||
@@ -623,6 +623,11 @@ The default is | |||
623 | Specifies whether user authentication based on GSSAPI is allowed. | 623 | Specifies whether user authentication based on GSSAPI is allowed. |
624 | The default is | 624 | The default is |
625 | .Dq no . | 625 | .Dq no . |
626 | .It Cm GSSAPIKeyExchange | ||
627 | Specifies whether key exchange based on GSSAPI is allowed. GSSAPI key exchange | ||
628 | doesn't rely on ssh keys to verify host identity. | ||
629 | The default is | ||
630 | .Dq no . | ||
626 | .It Cm GSSAPICleanupCredentials | 631 | .It Cm GSSAPICleanupCredentials |
627 | Specifies whether to automatically destroy the user's credentials cache | 632 | Specifies whether to automatically destroy the user's credentials cache |
628 | on logout. | 633 | on logout. |
@@ -643,6 +648,11 @@ machine's default store. | |||
643 | This facility is provided to assist with operation on multi homed machines. | 648 | This facility is provided to assist with operation on multi homed machines. |
644 | The default is | 649 | The default is |
645 | .Dq yes . | 650 | .Dq yes . |
651 | .It Cm GSSAPIStoreCredentialsOnRekey | ||
652 | Controls whether the user's GSSAPI credentials should be updated following a | ||
653 | successful connection rekeying. This option can be used to accepted renewed | ||
654 | or updated credentials from a compatible client. The default is | ||
655 | .Dq no . | ||
646 | .It Cm HostbasedAcceptedKeyTypes | 656 | .It Cm HostbasedAcceptedKeyTypes |
647 | Specifies the key types that will be accepted for hostbased authentication | 657 | Specifies the key types that will be accepted for hostbased authentication |
648 | as a comma-separated pattern list. | 658 | as a comma-separated pattern list. |