diff options
Diffstat (limited to 'sshd_config')
-rw-r--r-- | sshd_config | 23 |
1 files changed, 16 insertions, 7 deletions
diff --git a/sshd_config b/sshd_config index 4957dd1a6..68c8752c0 100644 --- a/sshd_config +++ b/sshd_config | |||
@@ -1,4 +1,4 @@ | |||
1 | # $OpenBSD: sshd_config,v 1.73 2005/12/06 22:38:28 reyk Exp $ | 1 | # $OpenBSD: sshd_config,v 1.74 2006/07/19 13:07:10 dtucker Exp $ |
2 | 2 | ||
3 | # This is the sshd server system-wide configuration file. See | 3 | # This is the sshd server system-wide configuration file. See |
4 | # sshd_config(5) for more information. | 4 | # sshd_config(5) for more information. |
@@ -68,15 +68,18 @@ | |||
68 | # GSSAPI options | 68 | # GSSAPI options |
69 | #GSSAPIAuthentication no | 69 | #GSSAPIAuthentication no |
70 | #GSSAPICleanupCredentials yes | 70 | #GSSAPICleanupCredentials yes |
71 | #GSSAPIStrictAcceptorCheck yes | ||
72 | #GSSAPIKeyExchange no | ||
71 | 73 | ||
72 | # Set this to 'yes' to enable PAM authentication, account processing, | 74 | # Set this to 'yes' to enable PAM authentication, account processing, |
73 | # and session processing. If this is enabled, PAM authentication will | 75 | # and session processing. If this is enabled, PAM authentication will |
74 | # be allowed through the ChallengeResponseAuthentication mechanism. | 76 | # be allowed through the ChallengeResponseAuthentication and |
75 | # Depending on your PAM configuration, this may bypass the setting of | 77 | # PasswordAuthentication. Depending on your PAM configuration, |
76 | # PasswordAuthentication, PermitEmptyPasswords, and | 78 | # PAM authentication via ChallengeResponseAuthentication may bypass |
77 | # "PermitRootLogin without-password". If you just want the PAM account and | 79 | # the setting of "PermitRootLogin without-password". |
78 | # session checks to run without PAM authentication, then enable this but set | 80 | # If you just want the PAM account and session checks to run without |
79 | # ChallengeResponseAuthentication=no | 81 | # PAM authentication, then enable this but set PasswordAuthentication |
82 | # and ChallengeResponseAuthentication to 'no'. | ||
80 | #UsePAM no | 83 | #UsePAM no |
81 | 84 | ||
82 | #AllowTcpForwarding yes | 85 | #AllowTcpForwarding yes |
@@ -103,3 +106,9 @@ | |||
103 | 106 | ||
104 | # override default of no subsystems | 107 | # override default of no subsystems |
105 | Subsystem sftp /usr/libexec/sftp-server | 108 | Subsystem sftp /usr/libexec/sftp-server |
109 | |||
110 | # Example of overriding settings on a per-user basis | ||
111 | #Match User anoncvs | ||
112 | # X11Forwarding no | ||
113 | # AllowTcpForwarding no | ||
114 | # ForceCommand cvs server | ||