xref: /netbsd-src/crypto/external/bsd/openssh/dist/sshd_config (revision c7c727fae85036860d5bb848f2730ff419e2b060)
1#	$NetBSD: sshd_config,v 1.10 2013/03/29 16:19:46 christos Exp $
2#	$OpenBSD: sshd_config,v 1.89 2013/02/06 00:20:42 dtucker Exp $
3
4# This is the sshd server system-wide configuration file.  See
5# sshd_config(5) for more information.
6
7# The strategy used for options in the default sshd_config shipped with
8# OpenSSH is to specify options with their default value where
9# possible, but leave them commented.  Uncommented options override the
10# default value.
11
12#Port 22
13#AddressFamily any
14#ListenAddress 0.0.0.0
15#ListenAddress ::
16
17# The default requires explicit activation of protocol 1
18#Protocol 2
19
20# HostKey for protocol version 1
21#HostKey /etc/ssh/ssh_host_key
22# HostKeys for protocol version 2
23#HostKey /etc/ssh/ssh_host_rsa_key
24#HostKey /etc/ssh/ssh_host_dsa_key
25#HostKey /etc/ssh/ssh_host_ecdsa_key
26
27# Lifetime and size of ephemeral version 1 server key
28#KeyRegenerationInterval 1h
29#ServerKeyBits 1024
30
31# Logging
32# obsoletes QuietMode and FascistLogging
33#SyslogFacility AUTH
34#LogLevel INFO
35
36# Authentication:
37
38LoginGraceTime 600
39#PermitRootLogin no
40#StrictModes yes
41#MaxAuthTries 6
42#MaxSessions 10
43
44#RSAAuthentication yes
45#PubkeyAuthentication yes
46
47# The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2
48# but this is overridden so installations will only check .ssh/authorized_keys
49AuthorizedKeysFile	.ssh/authorized_keys
50
51#AuthorizedPrincipalsFile none
52
53#AuthorizedKeysCommand none
54#AuthorizedKeysCommandUser nobody
55
56# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
57#RhostsRSAAuthentication no
58# similar for protocol version 2
59#HostbasedAuthentication no
60# Change to yes if you don't trust ~/.ssh/known_hosts for
61# RhostsRSAAuthentication and HostbasedAuthentication
62#IgnoreUserKnownHosts no
63# Don't read the user's ~/.rhosts and ~/.shosts files
64#IgnoreRhosts yes
65
66# To disable password authentication, set this and UsePam to no
67#PasswordAuthentication yes
68#PermitEmptyPasswords no
69
70# Change to no to disable s/key passwords
71#ChallengeResponseAuthentication yes
72
73# Kerberos options
74#KerberosAuthentication no
75#KerberosOrLocalPasswd yes
76#KerberosTicketCleanup yes
77#KerberosGetAFSToken no
78
79# GSSAPI options
80#GSSAPIAuthentication no
81#GSSAPICleanupCredentials yes
82
83#AllowAgentForwarding yes
84#AllowTcpForwarding yes
85#GatewayPorts no
86#X11Forwarding no
87# If you use xorg from pkgsrc then uncomment the following line.
88#XAuthLocation /usr/pkg/bin/xauth
89#X11DisplayOffset 10
90#X11UseLocalhost yes
91#PrintMotd yes
92#PrintLastLog yes
93#TCPKeepAlive yes
94#UseLogin no
95UsePrivilegeSeparation sandbox
96UsePam yes
97#PermitUserEnvironment no
98#Compression delayed
99#ClientAliveInterval 0
100#ClientAliveCountMax 3
101#UseDNS yes
102#PidFile /var/run/sshd.pid
103#MaxStartups 10:30:100
104#PermitTunnel no
105#ChrootDirectory none
106#VersionAddendum none
107
108# no default banner path
109#Banner none
110
111# here are the new patched ldap related tokens
112# entries in your LDAP must have posixAccount & ldapPublicKey objectclass
113#UseLPK yes
114#LpkLdapConf /etc/ldap.conf
115#LpkServers  ldap://10.1.7.1/ ldap://10.1.7.2/
116#LpkUserDN   ou=users,dc=phear,dc=org
117#LpkGroupDN  ou=groups,dc=phear,dc=org
118#LpkBindDN cn=Manager,dc=phear,dc=org
119#LpkBindPw secret
120#LpkServerGroup mail
121#LpkFilter (hostAccess=master.phear.org)
122#LpkForceTLS no
123#LpkSearchTimelimit 3
124#LpkBindTimelimit 3
125#LpkPubKeyAttr sshPublicKey
126
127# override default of no subsystems
128Subsystem	sftp	/usr/libexec/sftp-server
129
130# the following are HPN related configuration options
131# tcp receive buffer polling. disable in non autotuning kernels
132#TcpRcvBufPoll yes
133
134# allow the use of the none cipher
135#NoneEnabled no
136
137# disable hpn performance boosts.
138#HPNDisabled no
139
140# buffer size for hpn to non-hpn connections
141#HPNBufferSize 2048
142
143
144# Example of overriding settings on a per-user basis
145#Match User anoncvs
146#	X11Forwarding no
147#	AllowTcpForwarding no
148#	ForceCommand cvs server
149