diff options
Diffstat (limited to 'sshd_config.5')
-rw-r--r-- | sshd_config.5 | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/sshd_config.5 b/sshd_config.5 index 6dce0c70c..033149695 100644 --- a/sshd_config.5 +++ b/sshd_config.5 | |||
@@ -564,12 +564,40 @@ Specifies whether user authentication based on GSSAPI is allowed. | |||
564 | The default is | 564 | The default is |
565 | .Dq no . | 565 | .Dq no . |
566 | Note that this option applies to protocol version 2 only. | 566 | Note that this option applies to protocol version 2 only. |
567 | .It Cm GSSAPIKeyExchange | ||
568 | Specifies whether key exchange based on GSSAPI is allowed. GSSAPI key exchange | ||
569 | doesn't rely on ssh keys to verify host identity. | ||
570 | The default is | ||
571 | .Dq no . | ||
572 | Note that this option applies to protocol version 2 only. | ||
567 | .It Cm GSSAPICleanupCredentials | 573 | .It Cm GSSAPICleanupCredentials |
568 | Specifies whether to automatically destroy the user's credentials cache | 574 | Specifies whether to automatically destroy the user's credentials cache |
569 | on logout. | 575 | on logout. |
570 | The default is | 576 | The default is |
571 | .Dq yes . | 577 | .Dq yes . |
572 | Note that this option applies to protocol version 2 only. | 578 | Note that this option applies to protocol version 2 only. |
579 | .It Cm GSSAPIStrictAcceptorCheck | ||
580 | Determines whether to be strict about the identity of the GSSAPI acceptor | ||
581 | a client authenticates against. If | ||
582 | .Dq yes | ||
583 | then the client must authenticate against the | ||
584 | .Pa host | ||
585 | service on the current hostname. If | ||
586 | .Dq no | ||
587 | then the client may authenticate against any service key stored in the | ||
588 | machine's default store. This facility is provided to assist with operation | ||
589 | on multi homed machines. | ||
590 | The default is | ||
591 | .Dq yes . | ||
592 | Note that this option applies only to protocol version 2 GSSAPI connections, | ||
593 | and setting it to | ||
594 | .Dq no | ||
595 | may only work with recent Kerberos GSSAPI libraries. | ||
596 | .It Cm GSSAPIStoreCredentialsOnRekey | ||
597 | Controls whether the user's GSSAPI credentials should be updated following a | ||
598 | successful connection rekeying. This option can be used to accepted renewed | ||
599 | or updated credentials from a compatible client. The default is | ||
600 | .Dq no . | ||
573 | .It Cm HostbasedAcceptedKeyTypes | 601 | .It Cm HostbasedAcceptedKeyTypes |
574 | Specifies the key types that will be accepted for hostbased authentication | 602 | Specifies the key types that will be accepted for hostbased authentication |
575 | as a comma-separated pattern list. | 603 | as a comma-separated pattern list. |