summaryrefslogtreecommitdiff
path: root/sshd_config.5
diff options
context:
space:
mode:
authorderaadt@openbsd.org <deraadt@openbsd.org>2015-01-22 20:24:41 +0000
committerDamien Miller <djm@mindrot.org>2015-01-26 23:58:53 +1100
commitdcff5810a11195c57e1b3343c0d6b6f2b9974c11 (patch)
tree5e20d4f160ed4d39198fb42fcd66fe19fb07ab56 /sshd_config.5
parent087266ec33c76fc8d54ac5a19efacf2f4a4ca076 (diff)
upstream commit
Provide a warning about chroot misuses (which sadly, seem to have become quite popular because shiny). sshd cannot detect/manage/do anything about these cases, best we can do is warn in the right spot in the man page. ok markus
Diffstat (limited to 'sshd_config.5')
-rw-r--r--sshd_config.517
1 files changed, 13 insertions, 4 deletions
diff --git a/sshd_config.5 b/sshd_config.5
index 88fe90193..3b809c28d 100644
--- a/sshd_config.5
+++ b/sshd_config.5
@@ -33,8 +33,8 @@
33.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 33.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
34.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 34.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
35.\" 35.\"
36.\" $OpenBSD: sshd_config.5,v 1.189 2015/01/13 07:39:19 djm Exp $ 36.\" $OpenBSD: sshd_config.5,v 1.190 2015/01/22 20:24:41 deraadt Exp $
37.Dd $Mdocdate: January 13 2015 $ 37.Dd $Mdocdate: January 22 2015 $
38.Dt SSHD_CONFIG 5 38.Dt SSHD_CONFIG 5
39.Os 39.Os
40.Sh NAME 40.Sh NAME
@@ -330,8 +330,10 @@ The default is
330Specifies the pathname of a directory to 330Specifies the pathname of a directory to
331.Xr chroot 2 331.Xr chroot 2
332to after authentication. 332to after authentication.
333All components of the pathname must be root-owned directories that are 333At session startup
334not writable by any other user or group. 334.Xr sshd 8
335checks that all components of the pathname are root-owned directories
336which are not writable by any other user or group.
335After the chroot, 337After the chroot,
336.Xr sshd 8 338.Xr sshd 8
337changes the working directory to the user's home directory. 339changes the working directory to the user's home directory.
@@ -368,6 +370,13 @@ inside the chroot directory on some operating systems (see
368.Xr sftp-server 8 370.Xr sftp-server 8
369for details). 371for details).
370.Pp 372.Pp
373For safety, it is very important that the directory heirarchy be
374prevented from modification by other processes on the system (especially
375those outside the jail).
376Misconfiguration can lead to unsafe environments which
377.Xr sshd 8
378cannot detect.
379.Pp
371The default is not to 380The default is not to
372.Xr chroot 2 . 381.Xr chroot 2 .
373.It Cm Ciphers 382.It Cm Ciphers