summaryrefslogtreecommitdiff
path: root/ssh-add.0
blob: 0e2d1bca67cac21137cb8024396ae475679c94c1 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
SSHM-bM-^@M-^PADD(1)                BSD General Commands Manual               SSHM-bM-^@M-^PADD(1)

^[[1mNAME^[[0m
     ^[[1msshM-bM-^@M-^Padd ^[[22mM-bMM-^R adds RSA or DSA identities to the authentication agent

^[[1mSYNOPSIS^[[0m
     ^[[1msshM-bM-^@M-^Padd ^[[22m[^[[1mM-bMM-^RlLdDxXc^[[22m] [^[[1mM-bMM-^Rt ^[[4m^[[22mlife^[[24m] [^[[4mfile^[[24m ^[[4m...^[[24m]
     ^[[1msshM-bM-^@M-^Padd M-bMM-^Rs ^[[4m^[[22mreader^[[0m
     ^[[1msshM-bM-^@M-^Padd M-bMM-^Re ^[[4m^[[22mreader^[[0m

^[[1mDESCRIPTION^[[0m
     ^[[1msshM-bM-^@M-^Padd ^[[22madds RSA or DSA identities to the authentication agent,
     sshM-bM-^@M-^Pagent(1).  When run without arguments, it adds the files
     ^[[4m$HOME/.ssh/id_rsa^[[24m, ^[[4m$HOME/.ssh/id_dsa^[[24m and ^[[4m$HOME/.ssh/identity^[[24m.  AlternaM-bM-^@M-^P
     tive file names can be given on the command line.  If any file requires a
     passphrase, ^[[1msshM-bM-^@M-^Padd ^[[22masks for the passphrase from the user.  The
     passphrase is read from the userM-bM-^@M-^Ys tty.  ^[[1msshM-bM-^@M-^Padd ^[[22mretries the last
     passphrase if multiple identity files are given.

     The authentication agent must be running and must be an ancestor of the
     current process for ^[[1msshM-bM-^@M-^Padd ^[[22mto work.

     The options are as follows:

     ^[[1mM-bMM-^Rl      ^[[22mLists fingerprints of all identities currently represented by the
             agent.

     ^[[1mM-bMM-^RL      ^[[22mLists public key parameters of all identities currently repreM-bM-^@M-^P
             sented by the agent.

     ^[[1mM-bMM-^Rd      ^[[22mInstead of adding the identity, removes the identity from the
             agent.

     ^[[1mM-bMM-^RD      ^[[22mDeletes all identities from the agent.

     ^[[1mM-bMM-^Rx      ^[[22mLock the agent with a password.

     ^[[1mM-bMM-^RX      ^[[22mUnlock the agent.

     ^[[1mM-bMM-^Rt ^[[4m^[[22mlife^[[0m
             Set a maximum lifetime when adding identities to an agent.  The
             lifetime may be specified in seconds or in a time format speciM-bM-^@M-^P
             fied in sshd_config(5).

     ^[[1mM-bMM-^Rc      ^[[22mIndicates that added identities should be subject to confirmation
             before being used for authentication. Confirmation is performed
             by the SSH_ASKPASS program mentioned below. Successful confirmaM-bM-^@M-^P
             tion is signaled by a zero exit status from the SSH_ASKPASS proM-bM-^@M-^P
             gram, rather than text entered into the requester.

     ^[[1mM-bMM-^Rs ^[[4m^[[22mreader^[[0m
             Add key in smartcard ^[[4mreader^[[24m.

     ^[[1mM-bMM-^Re ^[[4m^[[22mreader^[[0m
             Remove key in smartcard ^[[4mreader^[[24m.

^[[1mFILES^[[0m
     $HOME/.ssh/identity
             Contains the protocol version 1 RSA authentication identity of
             the user.

     $HOME/.ssh/id_dsa
             Contains the protocol version 2 DSA authentication identity of
             the user.

     $HOME/.ssh/id_rsa
             Contains the protocol version 2 RSA authentication identity of
             the user.

     Identity files should not be readable by anyone but the user.  Note that
     ^[[1msshM-bM-^@M-^Padd ^[[22mignores identity files if they are accessible by others.

^[[1mENVIRONMENT^[[0m
     DISPLAY and SSH_ASKPASS
             If ^[[1msshM-bM-^@M-^Padd ^[[22mneeds a passphrase, it will read the passphrase from
             the current terminal if it was run from a terminal.  If ^[[1msshM-bM-^@M-^Padd^[[0m
             does not have a terminal associated with it but DISPLAY and
             SSH_ASKPASS are set, it will execute the program specified by
             SSH_ASKPASS and open an X11 window to read the passphrase.  This
             is particularly useful when calling ^[[1msshM-bM-^@M-^Padd ^[[22mfrom a ^[[4m.Xsession^[[24m or
             related script.  (Note that on some machines it may be necessary
             to redirect the input from ^[[4m/dev/null^[[24m to make this work.)

     SSH_AUTH_SOCK
             Identifies the path of a unixM-bM-^@M-^Pdomain socket used to communicate
             with the agent.

^[[1mDIAGNOSTICS^[[0m
     Exit status is 0 on success, 1 if the specified command fails, and 2 if
     ^[[1msshM-bM-^@M-^Padd ^[[22mis unable to contact the authentication agent.

^[[1mAUTHORS^[[0m
     OpenSSH is a derivative of the original and free ssh 1.2.12 release by
     Tatu Ylonen.  Aaron Campbell, Bob Beck, Markus Friedl, Niels Provos, Theo
     de Raadt and Dug Song removed many bugs, reM-bM-^@M-^Padded newer features and creM-bM-^@M-^P
     ated OpenSSH.  Markus Friedl contributed the support for SSH protocol
     versions 1.5 and 2.0.

^[[1mSEE ALSO^[[0m
     ssh(1), sshM-bM-^@M-^Pagent(1), sshM-bM-^@M-^Pkeygen(1), sshd(8)

BSD                           September 25, 1999                           BSD