summaryrefslogtreecommitdiff
path: root/sshd_config.5
diff options
context:
space:
mode:
Diffstat (limited to 'sshd_config.5')
-rw-r--r--sshd_config.514
1 files changed, 14 insertions, 0 deletions
diff --git a/sshd_config.5 b/sshd_config.5
index a7a7227b2..dab26e079 100644
--- a/sshd_config.5
+++ b/sshd_config.5
@@ -615,6 +615,20 @@ are refused if the number of unauthenticated connections reaches
615Specifies whether password authentication is allowed. 615Specifies whether password authentication is allowed.
616The default is 616The default is
617.Dq yes . 617.Dq yes .
618.It Cm PermitBlacklistedKeys
619Specifies whether
620.Xr sshd 8
621should allow keys recorded in its blacklist of known-compromised keys (see
622.Xr ssh-vulnkey 1 ) .
623If
624.Dq yes ,
625then attempts to authenticate with compromised keys will be logged but
626accepted.
627If
628.Dq no ,
629then attempts to authenticate with compromised keys will be rejected.
630The default is
631.Dq no .
618.It Cm PermitEmptyPasswords 632.It Cm PermitEmptyPasswords
619When password authentication is allowed, it specifies whether the 633When password authentication is allowed, it specifies whether the
620server allows login to accounts with empty password strings. 634server allows login to accounts with empty password strings.