From wyllys@borg.sfbay.sun.com Tue Oct  6 07:27:21 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n96ERLtg007062
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 6 Oct 2009 07:27:21 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n96ERFl2041081
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.Com>; Tue, 6 Oct 2009 08:27:20 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR300F17K5J6P00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.Com
 (ORCPT PSARC-ext@Sun.Com); Tue, 06 Oct 2009 07:27:19 -0700 (PDT)
Received: from borg.sfbay ([10.5.240.20]) by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR300EOBK5JRC00@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.Com (ORCPT PSARC-ext@Sun.Com); Tue,
 06 Oct 2009 07:27:19 -0700 (PDT)
Received: from borg.sfbay (localhost [127.0.0.1])
	by borg.sfbay (8.14.3+Sun/8.14.3) with ESMTP id n96EQoaW021120; Tue,
 06 Oct 2009 07:26:50 -0700 (PDT)
Received: (from wyllys@localhost)	by borg.sfbay (8.14.3+Sun/8.14.3/Submit)
 id n96EQnFh021116; Tue, 06 Oct 2009 07:26:50 -0700 (PDT)
Date: Tue, 06 Oct 2009 07:26:50 -0700 (PDT)
From: Wyllys Ingersoll <wyllys@borg.sfbay.sun.com>
Subject: sshd match block option [PSARC/2009/531 FastTrack timeout 10/13/2009]
To: PSARC-ext@sun.com
Message-id: <200910061426.n96EQnFh021116@borg.sfbay>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1965


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 sshd match block option
    1.2. Name of Document Author/Supplier:
	 Author:  HuieYing Lee
    1.3  Date of This Document:
	06 October, 2009
4. Technical Description
1. Introduction

   1.1. Project/Component Working Name:

        The Match conditional block option for SunSSH server
        
   1.2. Name of Document Author/Supplier:

        HuieYing Lee
        
   1.3. Date of This Document:

        Oct 05 2009

4. Technical Description:

   The goal of this project is to implement the Match conditional block
   feature according to how OpenSSH implemented it in the 5.2p1 version
   (released 2009-02-22). This feature enables a customer to specify
   SSH server configuration options based on user, group, hostname, or
   address.

   This project introduces a Match conditional block in the sshd_config file,
   the SunSSH server configuration file. If all of the criteria on the Match
   line are satisfied, the keywords on the following lines override those
   set in the global section of the configuration file, until either another
   Match line or the end of the file.

   The pertinent SunSSH OpenCR's are:
     6655613 resync server's conditional Match block from OpenSSH
     6871707 need new tests for ssh server's conditonal Match block feature
             after putback of CR6655613
     6881438 sshd_config(4) man page needs to be updated after putback of
             CR6655613
     6885011 ssh section in the system admin guide needs to be updated after
             putback of CR6655613

   Attached are the sshd_config file and man page changes.
	(see PSARC case materials directory)

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Wyllys.Ingersoll@sun.com Tue Oct  6 07:31:23 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n96EVNoP007114
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 6 Oct 2009 07:31:23 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id n96EVL17010630
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 6 Oct 2009 07:31:22 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR30023HKCAOA00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 06 Oct 2009 07:31:22 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR300J9ZKC80040@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 06 Oct 2009 07:31:20 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n96EVK9c005988	for
 <PSARC-ext@sun.com>; Tue, 06 Oct 2009 14:31:20 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KR300C00K1V8400@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 06 Oct 2009 08:31:20 -0600 (MDT)
Received: from [192.168.1.50] (usr230.res.openband.net [216.40.74.230])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KR3007IXKC6NP20@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 06 Oct 2009 08:31:19 -0600 (MDT)
Date: Tue, 06 Oct 2009 10:31:18 -0400
From: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>
Subject: PSARC 2009/531
Sender: Wyllys.Ingersoll@sun.com
To: PSARC-ext <PSARC-ext@sun.com>
Message-id: <4ACB54B6.8060505@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.22 (X11/20090816)
Status: RO
Content-Length: 73462

This is a multi-part message in MIME format.

--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT


I am sponsoring the attached fastrack case for Huie-Ying Lee.  The
timer is set to expire in 1 week (10-13-2009).

The target is Nevada only, the submitter is requesting
minor patch binding.

-Wyllys Ingersoll



--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=ssh_match.spec
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=ssh_match.spec

1. Introduction

   1.1. Project/Component Working Name:

        The Match conditional block option for SunSSH server
        
   1.2. Name of Document Author/Supplier:

        HuieYing Lee
        
   1.3. Date of This Document:

        Oct 05 2009

4. Technical Description:

   The goal of this project is to implement the Match conditional block
   feature according to how OpenSSH implemented it in the 5.2p1 version
   (released 2009-02-22). This feature enables a customer to specify
   SSH server configuration options based on user, group, hostname, or
   address.

   This project introduces a Match conditional block in the sshd_config file,
   the SunSSH server configuration file. If all of the criteria on the Match
   line are satisfied, the keywords on the following lines override those
   set in the global section of the configuration file, until either another
   Match line or the end of the file.

   The pertinent SunSSH OpenCR's are:
     6655613 resync server's conditional Match block from OpenSSH
     6871707 need new tests for ssh server's conditonal Match block feature
             after putback of CR6655613
     6881438 sshd_config(4) man page needs to be updated after putback of
             CR6655613
     6885011 ssh section in the system admin guide needs to be updated after
             putback of CR6655613

   Attached are the sshd_config file and man page changes.


--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=sshd_config.diff
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.diff

*** sshd_config.orig	Fri Sep 11 16:42:18 2009
--- sshd_config.new	Fri Sep 11 16:41:53 2009
***************
*** 150,152 ****
--- 150,157 ----
  # Is pure RSA authentication allowed.
  # Default is yes
  RSAAuthentication yes
+ 
+ # Example of overriding settings on a per-user basis
+ #Match User anoncvs
+ #	X11Forwarding no
+ #	AllowTcpForwarding no


--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=sshd_config.man.diff
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.diff

*** sshd_config.man.orig	Fri Sep 11 16:16:43 2009
--- sshd_config.man.new	Fri Sep 25 10:57:36 2009
***************
*** 500,505 ****
--- 500,557 ----
  	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.
  
  
+      Match
+ 
+          Introduces a conditional block.  If all of the criteria on the
+          Match line are satisfied, the keywords on the following lines
+          override those set in the global section of the config file,
+          until either another Match line or the end of the file.  Note 
+          that Match blocks must be located at the end of the file, after
+          all the global settings.
+ 
+          The arguments to Match are one or more criteria-pattern pairs.
+          The available criteria are User, Group, Host, and Address.  The
+          match patterns may consist of single entries or comma-separated
+          lists and may use the wildcard (Asterisk "*" and question mark "?")
+          and negation operators.
+ 
+          The patterns in a Host criteria should be hostname. The patterns
+          in an Address criteria should be IP address, which may
+          additionally contain addresses to match in CIDR address/masklen
+          format, e.g. ``192.0.2.0/24'' or ``2001:DB8::/32''.
+          Note that the mask length provided must be consistent with the
+          address - it is an error to specify a mask length that is too
+          long for the address or one with bits set in this host portion
+          of the address.  For example, ``192.0.2.0/33'' and ``192.0.2.0/8''
+          respectively.
+ 
+          Only a subset of keywords may be used on the lines following a
+          Match keyword.  Available keywords are AllowTcpForwarding,
+          Banner, ChrootDirectory, GatewayPorts, GSSAPIAuthentication,
+          HostbasedAuthentication, KbdInteractiveAuthentication,
+          MaxAuthTries, PasswordAuthentication, PermitEmptyPasswords,
+          PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication,
+          RSAAuthentication, X11DisplayOffset, X11Forwarding and
+          X11UseLocalhost.
+ 
+          Example 1: Disallow user "testuser" to use TCP forwarding
+          Match User testuser
+ 	     AllowTcpForwarding no
+ 
+          Example 2: Display a special banner for users not in the
+                     "staff" group
+          Match Group *,!staff
+              Banner /etc/banner.text
+ 
+          Example 3: Allow root login from host "rootallowed.example.com"
+          Match Host rootallowed.example.com
+             PermitRootLogin yes
+ 	     
+          Example 4: Allow anyone to use GatewayPorts from the local net
+          Match Address 192.168.0.0/24
+              GatewayPorts yes
+ 
+ 
       MaxStartups
  
  	 Specifies the maximum number of  concurrent  unauthenti-


--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=sshd_config.man.new
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.new




File Formats					   sshd_config(4)



NAME
     sshd_config - sshd	configuration file

SYNOPSIS
     /etc/ssh/sshd_config


DESCRIPTION
     The  sshd(1M)   daemon   reads   configuration   data   from
     /etc/ssh/sshd_config  (or the file	specified with sshd -f on
     the command line).	The file  contains  keyword-value  pairs,
     one per line. A line starting with	a hash mark (#)	and empty
     lines are interpreted as comments.


     The sshd_config file supports the following keywords. Unless
     otherwise	noted,	keywords  and  their  arguments	are case-
     insensitive.

     AllowGroups

	 This keyword can be followed by a number of group names,
	 separated by spaces. If specified, login is allowed only
	 for users whose primary  group	 or  supplementary  group
	 list matches one of the patterns. Asterisk (*)	and ques-
	 tion mark (?) can be used as wildcards	in the	patterns.
	 Only  group names are valid; a	numerical group	ID is not
	 recognized. By	default, login is allowed  regardless  of
	 the primary group.


     AllowTcpForwarding

	 Specifies  whether  TCP  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  TCP  forwarding	does  not
	 improve security unless  users	 are  also  denied  shell
	 access, as they can always install their own forwarders.


     AllowUsers

	 This keyword can be followed by a number of user  names,
	 separated by spaces. If specified, login is allowed only
	 for user names	that match one of the patterns.	 Asterisk
	 (*)  and  question  mark (?) can be used as wildcards in
	 the patterns. Only user names	are  valid;  a	numerical
	 user  ID  is not recognized. By default login is allowed
	 regardless of the user	name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, restricting logins
	 to particular users from particular hosts.



SunOS 5.11	    Last change: 26 Mar	2009			1






File Formats					   sshd_config(4)



     AuthorizedKeysFile

	 Specifies the file that contains the  public  keys  that
	 can  be used for user authentication. AuthorizedKeysFile
	 can contain tokens of the form	%T, which are substituted
	 during	 connection  set-up.  The  following  tokens  are
	 defined: %% is	replaced by a literal %, %h  is	 replaced
	 by  the  home	directory of the user being authenticated
	 and %u	is replaced by the username of that  user.  After
	 expansion, AuthorizedKeysFile is taken	to be an absolute
	 path or one relative to the user's home  directory.  The
	 default is .ssh/authorized_keys.


     Banner

	 In some jurisdictions,	sending	a warning message  before
	 authentication	can be relevant	for getting legal protec-
	 tion. The contents of the specified file are sent to the
	 remote	 user  before  authentication  is  allowed.  This
	 option	is only	available  for	protocol  version  2.  By
	 default, no banner is displayed.


     ChrootDirectory

	 Specifies a path to chroot(2) to  after  authentication.
	 This  path,  and  all its components, must be root-owned
	 directories that are not writable by any other	 user  or
	 group.

	 The server always tries to change  to	the  user's  home
	 directory  locally  under the chrooted	environment but	a
	 failure to do so is not considered an	error.	In  addi-
	 tion,	the  path might	contain	the following tokens that
	 are expanded at runtime once  the  connecting	user  has
	 been authenticated: %%	is replaced by a literal %, %h is
	 replaced by the home directory	of the user being authen-
	 ticated,  and	%u  is	replaced  by the username of that
	 user.

	 The ChrootDirectory must contain the necessary	files and
	 directories  to  support  the	user's	session.  For  an
	 interactive SSH session this requires at least	a  user's
	 shell,	 shared	 libraries  needed  by the shell, dynamic
	 linker, and possibly basic  /dev  nodes  such	as  null,
	 zero,	stdin, stdout, stderr, random, and tty.	Addition-
	 ally, terminal	databases are needed for screen	 oriented
	 applications. For file	transfer sessions using	sftp with
	 the SSH protocol version 2, no	additional  configuration
	 of  the  environment is necessary if the in-process sftp
	 server	is used. See Subsystem for details.



SunOS 5.11	    Last change: 26 Mar	2009			2






File Formats					   sshd_config(4)



	 The default is	not to chroot(2).


     Ciphers

	 Specifies the ciphers allowed for  protocol  version  2.
	 Cipher	ordering on the	server side is not relevant. Mul-
	 tiple ciphers must be comma separated.

	 Valid ciphers are: aes128-ctr,	 aes192-ctr,  aes256-ctr,
	 aes128-cbc, aes192-cbc, aes256-cbc, arcfour, arcfour128,
	 arcfour256, 3des-cbc, and blowfish-cbc.

	 The default cipher list is:

	   aes128-ctr,aes192-ctr,aes256-ctr,arcfour128,
	   arcfour256,arcfour


	 Using CBC modes on the	server side  is	 not  recommended
	 due  to potential security issues in connection with the
	 SSH protocol version 2.


     ClientAliveCountMax

	 Sets the number of client alive  messages,  (see  Clien-
	 tAliveInterval), that can be sent without sshd	receiving
	 any messages back from	the client. If this threshold  is
	 reached while client alive messages are being sent, sshd
	 disconnects the client, terminating the session. The use
	 of   client   alive  messages	is  very  different  from
	 KeepAlive. The	client alive messages  are  sent  through
	 the  encrypted	 channel and therefore are not spoofable.
	 The TCP keepalive option enabled by KeepAlive is spoofa-
	 ble.  The  client  alive  mechanism  is  valuable when	a
	 client	or server depend on knowing when a connection has
	 become	inactive.

	 The default value is 3. If ClientAliveInterval	is set to
	 15,  and  ClientAliveCountMax	is  left  at the default,
	 unresponsive ssh clients are disconnected after approxi-
	 mately	45 seconds.


     ClientAliveInterval

	 Sets a	timeout	interval in seconds after  which,  if  no
	 data  has  been  received  from the client, sshd sends	a
	 message through  the  encrypted  channel  to  request	a
	 response  from	 the client. The default is 0, indicating
	 that these messages are not sent  to  the  client.  This



SunOS 5.11	    Last change: 26 Mar	2009			3






File Formats					   sshd_config(4)



	 option	applies	only to	protocol version 2.


     Compression

	 Controls whether the server allows the	client	to  nego-
	 tiate the use of compression. The default is yes.


     DenyGroups

	 Can be	followed by a number of	group names, separated by
	 spaces.  Users	 whose	primary	 group matches one of the
	 patterns are not allowed to log  in.  Asterisk	 (*)  and
	 question  mark	 (?) can be used as wildcards in the pat-
	 terns.	Only group names are valid; a numerical	group  ID
	 is  not recognized. By	default, login is allowed regard-
	 less of the primary group.


     DenyUsers

	 Can be	followed by a number of	user names, separated  by
	 spaces.  Login	 is  disallowed	for user names that match
	 one of	the patterns. Asterisk (*) and question	mark  (?)
	 can  be  used	as  wildcards  in the patterns.	Only user
	 names are valid; a numerical user ID is not  recognized.
	 By  default,  login  is  allowed  regardless of the user
	 name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, disallowing logins
	 to particular users from particular hosts.


     GatewayPorts

	 Specifies whether remote hosts	are allowed to connect to
	 ports	forwarded  for the client. By default, sshd binds
	 remote	port forwardings to the	 loopback  address.  This
	 prevents other	remote hosts from connecting to	forwarded
	 ports.	GatewayPorts can be used  to  specify  that  sshd
	 should	 bind  remote  port  forwardings  to the wildcard
	 address, thus allowing	remote hosts to	connect	 to  for-
	 warded	ports.

	 The argument can be no	to force remote	port  forwardings
	 to  be	 available  to	the local host only, yes to force
	 remote	port forwardings to bind to the	wildcard address,
	 or  clientspecified  to  allow	 the client to select the
	 address to which the forwarding is bound. The default is
	 no. See also RemoteForward in ssh_config(4).



SunOS 5.11	    Last change: 26 Mar	2009			4






File Formats					   sshd_config(4)



     GSSAPIAuthentication

	 Enables/disables  GSS-API   user   authentication.   The
	 default is yes.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIKeyExchange

	 Enables/disables  GSS-API-authenticated  key  exchanges.
	 The default is	yes.

	 This option also enables  the	use  of	 the  GSS-API  to
	 authenticate  the user	to server after	the key	exchange.
	 GSS-API key exchange  can  succeed  but  the  subsequent
	 authentication	using the GSS-API fail if the server does
	 not authorize the user's GSS principal	name to	the  tar-
	 get user account.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIStoreDelegatedCredentials

	 Enables/disables the use of  delegated	 GSS-API  creden-
	 tials on the server-side. The default is yes.

	 Specifically, this  option,  when  enabled,  causes  the
	 server	 to  store  delegated  GSS-API credentials in the
	 user's	default	GSS-API	credential store (which	 for  the
	 Kerberos V mechanism means /tmp/krb5cc_<uid>).

	 Note -

	   sshd	does not take any  steps  to  explicitly  destroy
	   stored  delegated  GSS-API credentials upon logout. It
	   is  the  responsibility  of	PAM  modules  to  destroy
	   credentials associated with a session.


     HostbasedAuthentication

	 Specifies whether  to	try  rhosts-based  authentication
	 with public key authentication. The argument must be yes
	 or no.	 The  default  is  no.	This  option  applies  to



SunOS 5.11	    Last change: 26 Mar	2009			5






File Formats					   sshd_config(4)



	 protocol  version  2 only and is similar to RhostsRSAAu-
	 thentication. See sshd(1M) for	guidelines on setting  up
	 host-based authentication.


     HostbasedUsesNameFromPacketOnly

	 Controls which	hostname is searched  for  in  the  files
	 ~/.shosts,  /etc/shosts.equiv,	 and /etc/hosts.equiv. If
	 this parameter	is set to yes, the server uses	the  name
	 the  client  claimed  for  itself  and	 signed	with that
	 host's	key. If	set to no, the default,	the  server  uses
	 the name to which the client's	IP address resolves.

	 Setting this parameter	to no disables host-based authen-
	 tication  when	 using NAT or when the client gets to the
	 server	indirectly through a port-forwarding firewall.


     HostKey

	 Specifies the file containing the private host	key  used
	 by  SSH. The default is /etc/ssh/ssh_host_key for proto-
	 col  version  1,   and	  /etc/ssh/ssh_host_rsa_key   and
	 /etc/ssh/ssh_host_dsa_key  for	 protocol version 2. sshd
	 refuses to use	a file if it  is  group/world-accessible.
	 It  is	 possible  to  have multiple host key files. rsa1
	 keys are used for version 1 and dsa or	rsa are	used  for
	 version 2 of the SSH protocol.


     IgnoreRhosts

	 Specifies that	.rhosts	and .shosts files are not used in
	 authentication.  /etc/hosts.equiv  and	/etc/shosts.equiv
	 are still used.  The  default	is  yes.  This	parameter
	 applies to both protocol versions 1 and 2.


     IgnoreUserKnownHosts

	 Specifies  whether  sshd  should   ignore   the   user's
	 $HOME/.ssh/known_hosts	 during	 RhostsRSAAuthentication.
	 The default is	no. This parameter applies to both proto-
	 col versions 1	and 2.


     KbdInteractiveAuthentication

	 Specifies  whether  authentication  by	 means	 of   the
	 "keyboard-interactive"	 authentication	 method	(and PAM)
	 is allowed. Defaults to yes. (Deprecated: this	parameter



SunOS 5.11	    Last change: 26 Mar	2009			6






File Formats					   sshd_config(4)



	 can only be set to yes.)


     KeepAlive

	 Specifies whether the system should send keepalive  mes-
	 sages	to the other side. If they are sent, death of the
	 connection or crash of	one of the machines  is	 properly
	 noticed. However, this	means that connections die if the
	 route is down temporarily, which can be an annoyance. On
	 the other hand, if keepalives are not sent, sessions can
	 hang indefinitely on the server, leaving ghost	users and
	 consuming server resources.

	 The default is	yes (to	send keepalives), and the  server
	 notices  if  the  network  goes  down or the client host
	 reboots. This avoids infinitely hanging sessions.

	 To disable keepalives,	the value should be set	to no  in
	 both the server and the client	configuration files.


     KeyRegenerationInterval

	 In protocol version  1,  the  ephemeral  server  key  is
	 automatically regenerated after this many seconds (if it
	 has been  used).  The	purpose	 of  regeneration  is  to
	 prevent  decrypting  captured sessions	by later breaking
	 into the machine and stealing the keys. The key is never
	 stored	 anywhere.  If	the  value is 0, the key is never
	 regenerated. The default is 3600 (seconds).


     ListenAddress

	 Specifies what	local address sshd should listen on.  The
	 following forms can be	used:

	   ListenAddress host|IPv4_addr|IPv6_addr
	   ListenAddress host|IPv4_addr:port
	   ListenAddress [host|IPv6_addr]:port

	 If port is not	specified, sshd	listens	 on  the  address
	 and  all prior	Port options specified.	The default is to
	 listen	on all local  addresses.  Multiple  ListenAddress
	 options  are  permitted.  Additionally, any Port options
	 must  precede	this  option   for   non-port	qualified
	 addresses.

	 The default is	to listen on all local addresses.  Multi-
	 ple  options  of  this	type are permitted. Additionally,
	 the Ports options must	precede	this option.



SunOS 5.11	    Last change: 26 Mar	2009			7






File Formats					   sshd_config(4)



     LoginGraceTime

	 The server disconnects	after this time	(in  seconds)  if
	 the user has not successfully logged in. If the value is
	 0, there is no	time limit. The	default	is 120 (seconds).


     LogLevel

	 Gives the verbosity level that	is used	when logging mes-
	 sages	from sshd. The possible	values are: QUIET, FATAL,
	 ERROR,	INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3.
	 The  default  is  INFO.  DEBUG2  and DEBUG3 each specify
	 higher	levels of debugging output.  Logging  with  level
	 DEBUG	violates  the  privacy of users	and is not recom-
	 mended.


     LookupClientHostnames

	 Specifies whether or not to lookup the	names of client's
	 addresses. Defaults to	yes.


     MACs

	 Specifies  the	 available  MAC	 (message  authentication
	 code)	algorithms. The	MAC algorithm is used in protocol
	 version 2 for data integrity protection. Multiple  algo-
	 rithms	 must  be  comma-separated.  The default is hmac-
	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.


     Match

         Introduces a conditional block.  If all of the criteria on the
         Match line are satisfied, the keywords on the following lines
         override those set in the global section of the config file,
         until either another Match line or the end of the file.  Note 
         that Match blocks must be located at the end of the file, after
         all the global settings.

         The arguments to Match are one or more criteria-pattern pairs.
         The available criteria are User, Group, Host, and Address.  The
         match patterns may consist of single entries or comma-separated
         lists and may use the wildcard (Asterisk "*" and question mark "?")
         and negation operators.

         The patterns in a Host criteria should be hostname. The patterns
         in an Address criteria should be IP address, which may
         additionally contain addresses to match in CIDR address/masklen
         format, e.g. ``192.0.2.0/24'' or ``2001:DB8::/32''.
         Note that the mask length provided must be consistent with the
         address - it is an error to specify a mask length that is too
         long for the address or one with bits set in this host portion
         of the address.  For example, ``192.0.2.0/33'' and ``192.0.2.0/8''
         respectively.

         Only a subset of keywords may be used on the lines following a
         Match keyword.  Available keywords are AllowTcpForwarding,
         Banner, ChrootDirectory, GatewayPorts, GSSAPIAuthentication,
         HostbasedAuthentication, KbdInteractiveAuthentication,
         MaxAuthTries, PasswordAuthentication, PermitEmptyPasswords,
         PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication,
         RSAAuthentication, X11DisplayOffset, X11Forwarding and
         X11UseLocalhost.

         Example 1: Disallow user "testuser" to use TCP forwarding
         Match User testuser
	     AllowTcpForwarding no

         Example 2: Display a special banner for users not in the
                    "staff" group
         Match Group *,!staff
             Banner /etc/banner.text

         Example 3: Allow root login from host "rootallowed.example.com"
         Match Host rootallowed.example.com
            PermitRootLogin yes
	     
         Example 4: Allow anyone to use GatewayPorts from the local net
         Match Address 192.168.0.0/24
             GatewayPorts yes


     MaxStartups

	 Specifies the maximum number of  concurrent  unauthenti-
	 cated connections to the sshd daemon. Additional connec-
	 tions are dropped until authentication	succeeds  or  the
	 LoginGraceTime	 expires for a connection. The default is
	 10.

	 Alternatively,	random	early  drop  can  be  enabled  by
	 specifying	the    three	colon-separated	   values
	 start:rate:full (for example,	10:30:60).  Referring  to
	 this  example,	 sshd  refuse  connection attempts with	a
	 probability of	rate/100 (30% in our  example)	if  there
	 are  currently	10 (from the start field) unauthenticated
	 connections. The probability increases	linearly and  all
	 connection  attempts  are refused if the number of unau-
	 thenticated connections reaches full (60  in  our  exam-
	 ple).




SunOS 5.11	    Last change: 26 Mar	2009			8






File Formats					   sshd_config(4)



     PasswordAuthentication

	 Specifies whether password  authentication  is	 allowed.
	 The default is	yes. This option applies to both protocol
	 versions 1 and	2.


     PermitEmptyPasswords

	 When password or keyboard-interactive authentication  is
	 allowed, it specifies whether the server allows login to
	 accounts with empty password strings.

	 If not	set then the /etc/default/login	PASSREQ	value  is
	 used instead.

	 PASSREQ=no is equivalent  to  PermitEmptyPasswords  yes.
	 PASSREQ=yes is	equivalent to PermitEmptyPasswords no. If
	 neither PermitEmptyPasswords  or  PASSREQ  are	 set  the
	 default is no.


     PermitRootLogin

	 Specifies whether the root can	log in using ssh(1).  The
	 argument   must   be	yes,   without-password,  forced-
	 commands-only,	or no. without-password	means  that  root
	 cannot	  be   authenticated   using  the  "password"  or
	 "keyboard-interactive"	 methods  (see	 description   of
	 KbdInteractiveAuthentication).	     forced-commands-only
	 means that authentication is allowed only for	publickey
	 (for  SSHv2, or RSA, for SSHv1) and only if the matching
	 authorized_keys  entry	 for  root  has	 a  command=<cmd>
	 option.

	 In Solaris, the  default  /etc/ssh/sshd_config	 file  is
	 shipped  with PermitRootLogin set to no. If unset by the
	 administrator,	   then	   CONSOLE     parameter     from
	 /etc/default/login  supplies  the  default value as fol-
	 lows: if the CONSOLE parameter	is not commented out  (it
	 can  even  be empty, that is, "CONSOLE="), then without-
	 password is used as default value. If	CONSOLE	 is  com-
	 mented	out, then the default for PermitRootLogin is yes.

	 The without-password and  forced-commands-only	 settings
	 are  useful for, for example, performing remote adminis-
	 tration  and  backups	using  trusted	public	keys  for
	 authentication	 of  the  remote client, without allowing
	 access	to the root account using passwords.






SunOS 5.11	    Last change: 26 Mar	2009			9






File Formats					   sshd_config(4)



     PermitUserEnvironment

	 Specifies whether a  user's  ~/.ssh/environment  on  the
	 server	 side  and  environment	 options  in  the Author-
	 izedKeysFile file are processed by sshd. The default  is
	 no.  Enabling environment processing can enable users to
	 bypass	access restrictions in some configurations  using
	 mechanisms such as LD_PRELOAD.

	 Environment setting from a  relevant  entry  in  Author-
	 izedKeysFile  file  is	 processed  only  if the user was
	 authenticated	using  the  public   key   authentication
	 method.  Of  the two files used, values of variables set
	 in ~/.ssh/environment are of higher priority.


     PidFile

	 Allows	  you	 to    specify	  an	alternative    to
	 /var/run/sshd.pid,  the default file for storing the PID
	 of the	sshd listening for connections.	See sshd(1M).


     Port

	 Specifies the port number  that  sshd	listens	 on.  The
	 default is 22.	Multiple options of this type are permit-
	 ted. See also ListenAddress.


     PrintLastLog

	 Specifies whether sshd	should display the date	and  time
	 when the user last logged in. The default is yes.


     PrintMotd

	 Specifies whether sshd	should display	the  contents  of
	 /etc/motd  when  a  user logs in interactively. (On some
	 systems it is also displayed by the  shell  or	 a  shell
	 startup file, such as /etc/profile.) The default is yes.


     Protocol

	 Specifies the protocol	versions sshd should  support  in
	 order	of  preference.	 The possible values are 1 and 2.
	 Multiple versions must	be comma-separated.  The  default
	 is  2,1.  This	 means that ssh	tries version 2	and falls
	 back to version 1 if version 2	is not available.




SunOS 5.11	    Last change: 26 Mar	2009		       10






File Formats					   sshd_config(4)



     PubkeyAuthentication

	 Specifies whether public key authentication is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 2	only.


     RhostsAuthentication

	 Specifies  whether  authentication   using   rhosts   or
	 /etc/hosts.equiv  files  is  sufficient.  Normally, this
	 method	should not be permitted	because	it  is	insecure.
	 RhostsRSAAuthentication  should be used instead, because
	 it performs RSA-based host authentication in addition to
	 normal	 rhosts	 or  /etc/hosts.equiv authentication. The
	 default is no.	This parameter applies only  to	 protocol
	 version 1.


     RhostsRSAAuthentication

	 Specifies whether rhosts or /etc/hosts.equiv authentica-
	 tion together with successful RSA host	authentication is
	 allowed. The default is no. This parameter applies  only
	 to protocol version 1.


     RSAAuthentication

	 Specifies whether pure	RSA  authentication  is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 1	only.


     ServerKeyBits

	 Defines the number of bits  in	 the  ephemeral	 protocol
	 version  1 server key.	The minimum value is 512, and the
	 default is 768.


     StrictModes

	 Specifies whether sshd	should check file modes	and  own-
	 ership	 of  the  user's  files	and home directory before
	 accepting login.  This	 is  normally  desirable  because
	 novices  sometimes accidentally leave their directory or
	 files world-writable. The default is yes.


     Subsystem




SunOS 5.11	    Last change: 26 Mar	2009		       11






File Formats					   sshd_config(4)



	 Configures an external	subsystem (for	example,  a  file
	 transfer  daemon).  Arguments should be a subsystem name
	 and a command to execute  upon	 subsystem  request.  The
	 command   sftp-server(1M)   implements	  the  sftp  file
	 transfer subsystem.

	 Alternately, the name internal-sftp  implements  an  in-
	 process  sftp	server.	 This can simplify configurations
	 using ChrootDirectory to force	 a  different  filesystem
	 root on clients.

	 By default,  no  subsystems  are  defined.  This  option
	 applies to protocol version 2 only.


     SyslogFacility

	 Gives the facility code that is used when  logging  mes-
	 sages	from sshd. The possible	values are: DAEMON, USER,
	 AUTH, LOCAL0, LOCAL1, LOCAL2,	LOCAL3,	 LOCAL4,  LOCAL5,
	 LOCAL6, and LOCAL7. The default is AUTH.


     UseOpenSSLEngine

	 Specifies whether sshd	should use  the	 OpenSSL  PKCS#11
	 engine	 for  offloading  cryptographic	operations to the
	 Cryptographic Framework.  Cryptographic  operations  are
	 accelerated  according	 to the	available installed plug-
	 ins. When no suitable plug-ins	are present  this  option
	 does not have an effect. The default is yes.


     VerifyReverseMapping

	 Specifies whether sshd	should try to verify  the  remote
	 host  name and	check that the resolved	host name for the
	 remote	IP address maps	back to	the very same IP address.
	 (A  yes  setting means	"verify".) Setting this	parameter
	 to no can be useful where DNS servers might be	down  and
	 thus cause sshd to spend much time trying to resolve the
	 client's IP address to	a name.	This  feature  is  useful
	 for Internet-facing servers. The default is no.


     X11DisplayOffset

	 Specifies the first display number available for  sshd's
	 X11 forwarding. This prevents sshd from interfering with
	 real X11 servers. The default is 10.





SunOS 5.11	    Last change: 26 Mar	2009		       12






File Formats					   sshd_config(4)



     X11Forwarding

	 Specifies  whether  X11  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  X11  forwarding	does  not
	 improve security in any way, as users can always install
	 their own forwarders.

	 When X11 forwarding is	enabled, there can be  additional
	 exposure  to  the  server  and	to client displays if the
	 sshd proxy display is configured to listen on the  wild-
	 card address (see X11UseLocalhost). However, this is not
	 the default. Additionally, the	 authentication	 spoofing
	 and  authentication  data  verification and substitution
	 occur on the client side. The security	risk of	using X11
	 forwarding  is	 that the client's X11 display server can
	 be exposed to attack when the ssh client  requests  for-
	 warding    (see   the	 warnings   for	  ForwardX11   in
	 ssh_config(4)). A system administrator	who wants to pro-
	 tect  clients that expose themselves to attack	by unwit-
	 tingly	requesting X11 forwarding, should  specify  a  no
	 setting.

	 Disabling X11 forwarding does	not  prevent  users  from
	 forwarding  X11  traffic,  as	users  can always install
	 their own forwarders.


     X11UseLocalhost

	 Specifies whether sshd	should bind  the  X11  forwarding
	 server	 to  the  loopback  address  or	 to  the wildcard
	 address. By default, sshd binds the forwarding	server to
	 the  loopback	address	and sets the hostname part of the
	 DISPLAY environment variable to localhost. This prevents
	 remote	 hosts from connecting to the proxy display. How-
	 ever, some older X11 clients  might  not  function  with
	 this  configuration. X11UseLocalhost can be set to no to
	 specify that the forwarding server should  be	bound  to
	 the  wildcard	address.  The argument must be yes or no.
	 The default is	yes.


     XAuthLocation

	 Specifies the location	 of  the  xauth(1)  program.  The
	 default  is /usr/X11/bin/xauth	and sshd attempts to open
	 it when X11 forwarding	is enabled.


  Time Formats
     sshd command-line arguments and configuration  file  options
     that  specify  time can be	expressed using	a sequence of the



SunOS 5.11	    Last change: 26 Mar	2009		       13






File Formats					   sshd_config(4)



     form: time[qualifier,] where  time	 is  a	positive  integer
     value and qualifier is one	of the following:

     <none>    seconds


     s | S     seconds


     m | M     minutes


     h | H     hours


     d | D     days


     w |       weeks



     Each element of the sequence is added together to	calculate
     the total time value. For example:

     600      600 seconds (10 minutes)


     10m      10 minutes


     1h30m    1	hour, 30 minutes (90 minutes)


FILES
     /etc/ssh/sshd_config    Contains  configuration   data   for
			     sshd.  This  file should be writable
			     by	root only, but it is  recommended
			     (though  not  necessary)  that it be
			     world-readable.


ATTRIBUTES
     See attributes(5) for descriptions	of the	following  attri-
     butes:










SunOS 5.11	    Last change: 26 Mar	2009		       14






File Formats					   sshd_config(4)



     ____________________________________________________________
    |	    ATTRIBUTE TYPE	  |	  ATTRIBUTE VALUE	|
    |_____________________________|_____________________________|
    | Availability		  | SUNWsshu			|
    |_____________________________|_____________________________|
    | Interface	Stability	  | Uncommitted			|
    |_____________________________|_____________________________|


SEE ALSO
     login(1), sshd(1M), chroot(2), ssh_config(4), attributes(5),
     kerberos(5)

AUTHORS
     OpenSSH is	a derivative of	the original and free ssh  1.2.12
     release  by  Tatu	Ylonen.	 Aaron Campbell, Bob Beck, Markus
     Friedl, Niels Provos, Theo	de Raadt, and  Dug  Song  removed
     many  bugs,  re-added  recent features, and created OpenSSH.
     Markus Friedl contributed the support for SSH protocol  ver-
     sions  1.5	 and  2.0. Niels Provos	and Markus Friedl contri-
     buted support for privilege separation.


































SunOS 5.11	    Last change: 26 Mar	2009		       15





--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=sshd_config.man.orig
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.orig




File Formats					   sshd_config(4)



NAME
     sshd_config - sshd	configuration file

SYNOPSIS
     /etc/ssh/sshd_config


DESCRIPTION
     The  sshd(1M)   daemon   reads   configuration   data   from
     /etc/ssh/sshd_config  (or the file	specified with sshd -f on
     the command line).	The file  contains  keyword-value  pairs,
     one per line. A line starting with	a hash mark (#)	and empty
     lines are interpreted as comments.


     The sshd_config file supports the following keywords. Unless
     otherwise	noted,	keywords  and  their  arguments	are case-
     insensitive.

     AllowGroups

	 This keyword can be followed by a number of group names,
	 separated by spaces. If specified, login is allowed only
	 for users whose primary  group	 or  supplementary  group
	 list matches one of the patterns. Asterisk (*)	and ques-
	 tion mark (?) can be used as wildcards	in the	patterns.
	 Only  group names are valid; a	numerical group	ID is not
	 recognized. By	default, login is allowed  regardless  of
	 the primary group.


     AllowTcpForwarding

	 Specifies  whether  TCP  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  TCP  forwarding	does  not
	 improve security unless  users	 are  also  denied  shell
	 access, as they can always install their own forwarders.


     AllowUsers

	 This keyword can be followed by a number of user  names,
	 separated by spaces. If specified, login is allowed only
	 for user names	that match one of the patterns.	 Asterisk
	 (*)  and  question  mark (?) can be used as wildcards in
	 the patterns. Only user names	are  valid;  a	numerical
	 user  ID  is not recognized. By default login is allowed
	 regardless of the user	name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, restricting logins
	 to particular users from particular hosts.



SunOS 5.11	    Last change: 26 Mar	2009			1






File Formats					   sshd_config(4)



     AuthorizedKeysFile

	 Specifies the file that contains the  public  keys  that
	 can  be used for user authentication. AuthorizedKeysFile
	 can contain tokens of the form	%T, which are substituted
	 during	 connection  set-up.  The  following  tokens  are
	 defined: %% is	replaced by a literal %, %h  is	 replaced
	 by  the  home	directory of the user being authenticated
	 and %u	is replaced by the username of that  user.  After
	 expansion, AuthorizedKeysFile is taken	to be an absolute
	 path or one relative to the user's home  directory.  The
	 default is .ssh/authorized_keys.


     Banner

	 In some jurisdictions,	sending	a warning message  before
	 authentication	can be relevant	for getting legal protec-
	 tion. The contents of the specified file are sent to the
	 remote	 user  before  authentication  is  allowed.  This
	 option	is only	available  for	protocol  version  2.  By
	 default, no banner is displayed.


     ChrootDirectory

	 Specifies a path to chroot(2) to  after  authentication.
	 This  path,  and  all its components, must be root-owned
	 directories that are not writable by any other	 user  or
	 group.

	 The server always tries to change  to	the  user's  home
	 directory  locally  under the chrooted	environment but	a
	 failure to do so is not considered an	error.	In  addi-
	 tion,	the  path might	contain	the following tokens that
	 are expanded at runtime once  the  connecting	user  has
	 been authenticated: %%	is replaced by a literal %, %h is
	 replaced by the home directory	of the user being authen-
	 ticated,  and	%u  is	replaced  by the username of that
	 user.

	 The ChrootDirectory must contain the necessary	files and
	 directories  to  support  the	user's	session.  For  an
	 interactive SSH session this requires at least	a  user's
	 shell,	 shared	 libraries  needed  by the shell, dynamic
	 linker, and possibly basic  /dev  nodes  such	as  null,
	 zero,	stdin, stdout, stderr, random, and tty.	Addition-
	 ally, terminal	databases are needed for screen	 oriented
	 applications. For file	transfer sessions using	sftp with
	 the SSH protocol version 2, no	additional  configuration
	 of  the  environment is necessary if the in-process sftp
	 server	is used. See Subsystem for details.



SunOS 5.11	    Last change: 26 Mar	2009			2






File Formats					   sshd_config(4)



	 The default is	not to chroot(2).


     Ciphers

	 Specifies the ciphers allowed for  protocol  version  2.
	 Cipher	ordering on the	server side is not relevant. Mul-
	 tiple ciphers must be comma separated.

	 Valid ciphers are: aes128-ctr,	 aes192-ctr,  aes256-ctr,
	 aes128-cbc, aes192-cbc, aes256-cbc, arcfour, arcfour128,
	 arcfour256, 3des-cbc, and blowfish-cbc.

	 The default cipher list is:

	   aes128-ctr,aes192-ctr,aes256-ctr,arcfour128,
	   arcfour256,arcfour


	 Using CBC modes on the	server side  is	 not  recommended
	 due  to potential security issues in connection with the
	 SSH protocol version 2.


     ClientAliveCountMax

	 Sets the number of client alive  messages,  (see  Clien-
	 tAliveInterval), that can be sent without sshd	receiving
	 any messages back from	the client. If this threshold  is
	 reached while client alive messages are being sent, sshd
	 disconnects the client, terminating the session. The use
	 of   client   alive  messages	is  very  different  from
	 KeepAlive. The	client alive messages  are  sent  through
	 the  encrypted	 channel and therefore are not spoofable.
	 The TCP keepalive option enabled by KeepAlive is spoofa-
	 ble.  The  client  alive  mechanism  is  valuable when	a
	 client	or server depend on knowing when a connection has
	 become	inactive.

	 The default value is 3. If ClientAliveInterval	is set to
	 15,  and  ClientAliveCountMax	is  left  at the default,
	 unresponsive ssh clients are disconnected after approxi-
	 mately	45 seconds.


     ClientAliveInterval

	 Sets a	timeout	interval in seconds after  which,  if  no
	 data  has  been  received  from the client, sshd sends	a
	 message through  the  encrypted  channel  to  request	a
	 response  from	 the client. The default is 0, indicating
	 that these messages are not sent  to  the  client.  This



SunOS 5.11	    Last change: 26 Mar	2009			3






File Formats					   sshd_config(4)



	 option	applies	only to	protocol version 2.


     Compression

	 Controls whether the server allows the	client	to  nego-
	 tiate the use of compression. The default is yes.


     DenyGroups

	 Can be	followed by a number of	group names, separated by
	 spaces.  Users	 whose	primary	 group matches one of the
	 patterns are not allowed to log  in.  Asterisk	 (*)  and
	 question  mark	 (?) can be used as wildcards in the pat-
	 terns.	Only group names are valid; a numerical	group  ID
	 is  not recognized. By	default, login is allowed regard-
	 less of the primary group.


     DenyUsers

	 Can be	followed by a number of	user names, separated  by
	 spaces.  Login	 is  disallowed	for user names that match
	 one of	the patterns. Asterisk (*) and question	mark  (?)
	 can  be  used	as  wildcards  in the patterns.	Only user
	 names are valid; a numerical user ID is not  recognized.
	 By  default,  login  is  allowed  regardless of the user
	 name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, disallowing logins
	 to particular users from particular hosts.


     GatewayPorts

	 Specifies whether remote hosts	are allowed to connect to
	 ports	forwarded  for the client. By default, sshd binds
	 remote	port forwardings to the	 loopback  address.  This
	 prevents other	remote hosts from connecting to	forwarded
	 ports.	GatewayPorts can be used  to  specify  that  sshd
	 should	 bind  remote  port  forwardings  to the wildcard
	 address, thus allowing	remote hosts to	connect	 to  for-
	 warded	ports.

	 The argument can be no	to force remote	port  forwardings
	 to  be	 available  to	the local host only, yes to force
	 remote	port forwardings to bind to the	wildcard address,
	 or  clientspecified  to  allow	 the client to select the
	 address to which the forwarding is bound. The default is
	 no. See also RemoteForward in ssh_config(4).



SunOS 5.11	    Last change: 26 Mar	2009			4






File Formats					   sshd_config(4)



     GSSAPIAuthentication

	 Enables/disables  GSS-API   user   authentication.   The
	 default is yes.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIKeyExchange

	 Enables/disables  GSS-API-authenticated  key  exchanges.
	 The default is	yes.

	 This option also enables  the	use  of	 the  GSS-API  to
	 authenticate  the user	to server after	the key	exchange.
	 GSS-API key exchange  can  succeed  but  the  subsequent
	 authentication	using the GSS-API fail if the server does
	 not authorize the user's GSS principal	name to	the  tar-
	 get user account.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIStoreDelegatedCredentials

	 Enables/disables the use of  delegated	 GSS-API  creden-
	 tials on the server-side. The default is yes.

	 Specifically, this  option,  when  enabled,  causes  the
	 server	 to  store  delegated  GSS-API credentials in the
	 user's	default	GSS-API	credential store (which	 for  the
	 Kerberos V mechanism means /tmp/krb5cc_<uid>).

	 Note -

	   sshd	does not take any  steps  to  explicitly  destroy
	   stored  delegated  GSS-API credentials upon logout. It
	   is  the  responsibility  of	PAM  modules  to  destroy
	   credentials associated with a session.


     HostbasedAuthentication

	 Specifies whether  to	try  rhosts-based  authentication
	 with public key authentication. The argument must be yes
	 or no.	 The  default  is  no.	This  option  applies  to



SunOS 5.11	    Last change: 26 Mar	2009			5






File Formats					   sshd_config(4)



	 protocol  version  2 only and is similar to RhostsRSAAu-
	 thentication. See sshd(1M) for	guidelines on setting  up
	 host-based authentication.


     HostbasedUsesNameFromPacketOnly

	 Controls which	hostname is searched  for  in  the  files
	 ~/.shosts,  /etc/shosts.equiv,	 and /etc/hosts.equiv. If
	 this parameter	is set to yes, the server uses	the  name
	 the  client  claimed  for  itself  and	 signed	with that
	 host's	key. If	set to no, the default,	the  server  uses
	 the name to which the client's	IP address resolves.

	 Setting this parameter	to no disables host-based authen-
	 tication  when	 using NAT or when the client gets to the
	 server	indirectly through a port-forwarding firewall.


     HostKey

	 Specifies the file containing the private host	key  used
	 by  SSH. The default is /etc/ssh/ssh_host_key for proto-
	 col  version  1,   and	  /etc/ssh/ssh_host_rsa_key   and
	 /etc/ssh/ssh_host_dsa_key  for	 protocol version 2. sshd
	 refuses to use	a file if it  is  group/world-accessible.
	 It  is	 possible  to  have multiple host key files. rsa1
	 keys are used for version 1 and dsa or	rsa are	used  for
	 version 2 of the SSH protocol.


     IgnoreRhosts

	 Specifies that	.rhosts	and .shosts files are not used in
	 authentication.  /etc/hosts.equiv  and	/etc/shosts.equiv
	 are still used.  The  default	is  yes.  This	parameter
	 applies to both protocol versions 1 and 2.


     IgnoreUserKnownHosts

	 Specifies  whether  sshd  should   ignore   the   user's
	 $HOME/.ssh/known_hosts	 during	 RhostsRSAAuthentication.
	 The default is	no. This parameter applies to both proto-
	 col versions 1	and 2.


     KbdInteractiveAuthentication

	 Specifies  whether  authentication  by	 means	 of   the
	 "keyboard-interactive"	 authentication	 method	(and PAM)
	 is allowed. Defaults to yes. (Deprecated: this	parameter



SunOS 5.11	    Last change: 26 Mar	2009			6






File Formats					   sshd_config(4)



	 can only be set to yes.)


     KeepAlive

	 Specifies whether the system should send keepalive  mes-
	 sages	to the other side. If they are sent, death of the
	 connection or crash of	one of the machines  is	 properly
	 noticed. However, this	means that connections die if the
	 route is down temporarily, which can be an annoyance. On
	 the other hand, if keepalives are not sent, sessions can
	 hang indefinitely on the server, leaving ghost	users and
	 consuming server resources.

	 The default is	yes (to	send keepalives), and the  server
	 notices  if  the  network  goes  down or the client host
	 reboots. This avoids infinitely hanging sessions.

	 To disable keepalives,	the value should be set	to no  in
	 both the server and the client	configuration files.


     KeyRegenerationInterval

	 In protocol version  1,  the  ephemeral  server  key  is
	 automatically regenerated after this many seconds (if it
	 has been  used).  The	purpose	 of  regeneration  is  to
	 prevent  decrypting  captured sessions	by later breaking
	 into the machine and stealing the keys. The key is never
	 stored	 anywhere.  If	the  value is 0, the key is never
	 regenerated. The default is 3600 (seconds).


     ListenAddress

	 Specifies what	local address sshd should listen on.  The
	 following forms can be	used:

	   ListenAddress host|IPv4_addr|IPv6_addr
	   ListenAddress host|IPv4_addr:port
	   ListenAddress [host|IPv6_addr]:port

	 If port is not	specified, sshd	listens	 on  the  address
	 and  all prior	Port options specified.	The default is to
	 listen	on all local  addresses.  Multiple  ListenAddress
	 options  are  permitted.  Additionally, any Port options
	 must  precede	this  option   for   non-port	qualified
	 addresses.

	 The default is	to listen on all local addresses.  Multi-
	 ple  options  of  this	type are permitted. Additionally,
	 the Ports options must	precede	this option.



SunOS 5.11	    Last change: 26 Mar	2009			7






File Formats					   sshd_config(4)



     LoginGraceTime

	 The server disconnects	after this time	(in  seconds)  if
	 the user has not successfully logged in. If the value is
	 0, there is no	time limit. The	default	is 120 (seconds).


     LogLevel

	 Gives the verbosity level that	is used	when logging mes-
	 sages	from sshd. The possible	values are: QUIET, FATAL,
	 ERROR,	INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3.
	 The  default  is  INFO.  DEBUG2  and DEBUG3 each specify
	 higher	levels of debugging output.  Logging  with  level
	 DEBUG	violates  the  privacy of users	and is not recom-
	 mended.


     LookupClientHostnames

	 Specifies whether or not to lookup the	names of client's
	 addresses. Defaults to	yes.


     MACs

	 Specifies  the	 available  MAC	 (message  authentication
	 code)	algorithms. The	MAC algorithm is used in protocol
	 version 2 for data integrity protection. Multiple  algo-
	 rithms	 must  be  comma-separated.  The default is hmac-
	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.


     MaxStartups

	 Specifies the maximum number of  concurrent  unauthenti-
	 cated connections to the sshd daemon. Additional connec-
	 tions are dropped until authentication	succeeds  or  the
	 LoginGraceTime	 expires for a connection. The default is
	 10.

	 Alternatively,	random	early  drop  can  be  enabled  by
	 specifying	the    three	colon-separated	   values
	 start:rate:full (for example,	10:30:60).  Referring  to
	 this  example,	 sshd  refuse  connection attempts with	a
	 probability of	rate/100 (30% in our  example)	if  there
	 are  currently	10 (from the start field) unauthenticated
	 connections. The probability increases	linearly and  all
	 connection  attempts  are refused if the number of unau-
	 thenticated connections reaches full (60  in  our  exam-
	 ple).




SunOS 5.11	    Last change: 26 Mar	2009			8






File Formats					   sshd_config(4)



     PasswordAuthentication

	 Specifies whether password  authentication  is	 allowed.
	 The default is	yes. This option applies to both protocol
	 versions 1 and	2.


     PermitEmptyPasswords

	 When password or keyboard-interactive authentication  is
	 allowed, it specifies whether the server allows login to
	 accounts with empty password strings.

	 If not	set then the /etc/default/login	PASSREQ	value  is
	 used instead.

	 PASSREQ=no is equivalent  to  PermitEmptyPasswords  yes.
	 PASSREQ=yes is	equivalent to PermitEmptyPasswords no. If
	 neither PermitEmptyPasswords  or  PASSREQ  are	 set  the
	 default is no.


     PermitRootLogin

	 Specifies whether the root can	log in using ssh(1).  The
	 argument   must   be	yes,   without-password,  forced-
	 commands-only,	or no. without-password	means  that  root
	 cannot	  be   authenticated   using  the  "password"  or
	 "keyboard-interactive"	 methods  (see	 description   of
	 KbdInteractiveAuthentication).	     forced-commands-only
	 means that authentication is allowed only for	publickey
	 (for  SSHv2, or RSA, for SSHv1) and only if the matching
	 authorized_keys  entry	 for  root  has	 a  command=<cmd>
	 option.

	 In Solaris, the  default  /etc/ssh/sshd_config	 file  is
	 shipped  with PermitRootLogin set to no. If unset by the
	 administrator,	   then	   CONSOLE     parameter     from
	 /etc/default/login  supplies  the  default value as fol-
	 lows: if the CONSOLE parameter	is not commented out  (it
	 can  even  be empty, that is, "CONSOLE="), then without-
	 password is used as default value. If	CONSOLE	 is  com-
	 mented	out, then the default for PermitRootLogin is yes.

	 The without-password and  forced-commands-only	 settings
	 are  useful for, for example, performing remote adminis-
	 tration  and  backups	using  trusted	public	keys  for
	 authentication	 of  the  remote client, without allowing
	 access	to the root account using passwords.






SunOS 5.11	    Last change: 26 Mar	2009			9






File Formats					   sshd_config(4)



     PermitUserEnvironment

	 Specifies whether a  user's  ~/.ssh/environment  on  the
	 server	 side  and  environment	 options  in  the Author-
	 izedKeysFile file are processed by sshd. The default  is
	 no.  Enabling environment processing can enable users to
	 bypass	access restrictions in some configurations  using
	 mechanisms such as LD_PRELOAD.

	 Environment setting from a  relevant  entry  in  Author-
	 izedKeysFile  file  is	 processed  only  if the user was
	 authenticated	using  the  public   key   authentication
	 method.  Of  the two files used, values of variables set
	 in ~/.ssh/environment are of higher priority.


     PidFile

	 Allows	  you	 to    specify	  an	alternative    to
	 /var/run/sshd.pid,  the default file for storing the PID
	 of the	sshd listening for connections.	See sshd(1M).


     Port

	 Specifies the port number  that  sshd	listens	 on.  The
	 default is 22.	Multiple options of this type are permit-
	 ted. See also ListenAddress.


     PrintLastLog

	 Specifies whether sshd	should display the date	and  time
	 when the user last logged in. The default is yes.


     PrintMotd

	 Specifies whether sshd	should display	the  contents  of
	 /etc/motd  when  a  user logs in interactively. (On some
	 systems it is also displayed by the  shell  or	 a  shell
	 startup file, such as /etc/profile.) The default is yes.


     Protocol

	 Specifies the protocol	versions sshd should  support  in
	 order	of  preference.	 The possible values are 1 and 2.
	 Multiple versions must	be comma-separated.  The  default
	 is  2,1.  This	 means that ssh	tries version 2	and falls
	 back to version 1 if version 2	is not available.




SunOS 5.11	    Last change: 26 Mar	2009		       10






File Formats					   sshd_config(4)



     PubkeyAuthentication

	 Specifies whether public key authentication is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 2	only.


     RhostsAuthentication

	 Specifies  whether  authentication   using   rhosts   or
	 /etc/hosts.equiv  files  is  sufficient.  Normally, this
	 method	should not be permitted	because	it  is	insecure.
	 RhostsRSAAuthentication  should be used instead, because
	 it performs RSA-based host authentication in addition to
	 normal	 rhosts	 or  /etc/hosts.equiv authentication. The
	 default is no.	This parameter applies only  to	 protocol
	 version 1.


     RhostsRSAAuthentication

	 Specifies whether rhosts or /etc/hosts.equiv authentica-
	 tion together with successful RSA host	authentication is
	 allowed. The default is no. This parameter applies  only
	 to protocol version 1.


     RSAAuthentication

	 Specifies whether pure	RSA  authentication  is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 1	only.


     ServerKeyBits

	 Defines the number of bits  in	 the  ephemeral	 protocol
	 version  1 server key.	The minimum value is 512, and the
	 default is 768.


     StrictModes

	 Specifies whether sshd	should check file modes	and  own-
	 ership	 of  the  user's  files	and home directory before
	 accepting login.  This	 is  normally  desirable  because
	 novices  sometimes accidentally leave their directory or
	 files world-writable. The default is yes.


     Subsystem




SunOS 5.11	    Last change: 26 Mar	2009		       11






File Formats					   sshd_config(4)



	 Configures an external	subsystem (for	example,  a  file
	 transfer  daemon).  Arguments should be a subsystem name
	 and a command to execute  upon	 subsystem  request.  The
	 command   sftp-server(1M)   implements	  the  sftp  file
	 transfer subsystem.

	 Alternately, the name internal-sftp  implements  an  in-
	 process  sftp	server.	 This can simplify configurations
	 using ChrootDirectory to force	 a  different  filesystem
	 root on clients.

	 By default,  no  subsystems  are  defined.  This  option
	 applies to protocol version 2 only.


     SyslogFacility

	 Gives the facility code that is used when  logging  mes-
	 sages	from sshd. The possible	values are: DAEMON, USER,
	 AUTH, LOCAL0, LOCAL1, LOCAL2,	LOCAL3,	 LOCAL4,  LOCAL5,
	 LOCAL6, and LOCAL7. The default is AUTH.


     UseOpenSSLEngine

	 Specifies whether sshd	should use  the	 OpenSSL  PKCS#11
	 engine	 for  offloading  cryptographic	operations to the
	 Cryptographic Framework.  Cryptographic  operations  are
	 accelerated  according	 to the	available installed plug-
	 ins. When no suitable plug-ins	are present  this  option
	 does not have an effect. The default is yes.


     VerifyReverseMapping

	 Specifies whether sshd	should try to verify  the  remote
	 host  name and	check that the resolved	host name for the
	 remote	IP address maps	back to	the very same IP address.
	 (A  yes  setting means	"verify".) Setting this	parameter
	 to no can be useful where DNS servers might be	down  and
	 thus cause sshd to spend much time trying to resolve the
	 client's IP address to	a name.	This  feature  is  useful
	 for Internet-facing servers. The default is no.


     X11DisplayOffset

	 Specifies the first display number available for  sshd's
	 X11 forwarding. This prevents sshd from interfering with
	 real X11 servers. The default is 10.





SunOS 5.11	    Last change: 26 Mar	2009		       12






File Formats					   sshd_config(4)



     X11Forwarding

	 Specifies  whether  X11  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  X11  forwarding	does  not
	 improve security in any way, as users can always install
	 their own forwarders.

	 When X11 forwarding is	enabled, there can be  additional
	 exposure  to  the  server  and	to client displays if the
	 sshd proxy display is configured to listen on the  wild-
	 card address (see X11UseLocalhost). However, this is not
	 the default. Additionally, the	 authentication	 spoofing
	 and  authentication  data  verification and substitution
	 occur on the client side. The security	risk of	using X11
	 forwarding  is	 that the client's X11 display server can
	 be exposed to attack when the ssh client  requests  for-
	 warding    (see   the	 warnings   for	  ForwardX11   in
	 ssh_config(4)). A system administrator	who wants to pro-
	 tect  clients that expose themselves to attack	by unwit-
	 tingly	requesting X11 forwarding, should  specify  a  no
	 setting.

	 Disabling X11 forwarding does	not  prevent  users  from
	 forwarding  X11  traffic,  as	users  can always install
	 their own forwarders.


     X11UseLocalhost

	 Specifies whether sshd	should bind  the  X11  forwarding
	 server	 to  the  loopback  address  or	 to  the wildcard
	 address. By default, sshd binds the forwarding	server to
	 the  loopback	address	and sets the hostname part of the
	 DISPLAY environment variable to localhost. This prevents
	 remote	 hosts from connecting to the proxy display. How-
	 ever, some older X11 clients  might  not  function  with
	 this  configuration. X11UseLocalhost can be set to no to
	 specify that the forwarding server should  be	bound  to
	 the  wildcard	address.  The argument must be yes or no.
	 The default is	yes.


     XAuthLocation

	 Specifies the location	 of  the  xauth(1)  program.  The
	 default  is /usr/X11/bin/xauth	and sshd attempts to open
	 it when X11 forwarding	is enabled.


  Time Formats
     sshd command-line arguments and configuration  file  options
     that  specify  time can be	expressed using	a sequence of the



SunOS 5.11	    Last change: 26 Mar	2009		       13






File Formats					   sshd_config(4)



     form: time[qualifier,] where  time	 is  a	positive  integer
     value and qualifier is one	of the following:

     <none>    seconds


     s | S     seconds


     m | M     minutes


     h | H     hours


     d | D     days


     w |       weeks



     Each element of the sequence is added together to	calculate
     the total time value. For example:

     600      600 seconds (10 minutes)


     10m      10 minutes


     1h30m    1	hour, 30 minutes (90 minutes)


FILES
     /etc/ssh/sshd_config    Contains  configuration   data   for
			     sshd.  This  file should be writable
			     by	root only, but it is  recommended
			     (though  not  necessary)  that it be
			     world-readable.


ATTRIBUTES
     See attributes(5) for descriptions	of the	following  attri-
     butes:










SunOS 5.11	    Last change: 26 Mar	2009		       14






File Formats					   sshd_config(4)



     ____________________________________________________________
    |	    ATTRIBUTE TYPE	  |	  ATTRIBUTE VALUE	|
    |_____________________________|_____________________________|
    | Availability		  | SUNWsshu			|
    |_____________________________|_____________________________|
    | Interface	Stability	  | Uncommitted			|
    |_____________________________|_____________________________|


SEE ALSO
     login(1), sshd(1M), chroot(2), ssh_config(4), attributes(5),
     kerberos(5)

AUTHORS
     OpenSSH is	a derivative of	the original and free ssh  1.2.12
     release  by  Tatu	Ylonen.	 Aaron Campbell, Bob Beck, Markus
     Friedl, Niels Provos, Theo	de Raadt, and  Dug  Song  removed
     many  bugs,  re-added  recent features, and created OpenSSH.
     Markus Friedl contributed the support for SSH protocol  ver-
     sions  1.5	 and  2.0. Niels Provos	and Markus Friedl contri-
     buted support for privilege separation.


































SunOS 5.11	    Last change: 26 Mar	2009		       15





--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=sshd_config.new
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.new

#
# Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
# Use is subject to license terms.
#
# Configuration file for sshd(1m) (see also sshd_config(4))

# Protocol versions supported
#
# The sshd shipped in this release of Solaris has support for major versions
# 1 and 2.  It is recommended due to security weaknesses in the v1 protocol
# that sites run only v2 if possible. Support for v1 is provided to help sites
# with existing ssh v1 clients/servers to transition. 
# Support for v1 may not be available in a future release of Solaris.
#
# To enable support for v1 an RSA1 key must be created with ssh-keygen(1).
# RSA and DSA keys for protocol v2 are created by /etc/init.d/sshd if they
# do not already exist, RSA1 keys for protocol v1 are not automatically created.

# Uncomment ONLY ONE of the following Protocol statements.

# Only v2 (recommended)
Protocol 2

# Both v1 and v2 (not recommended)
#Protocol 2,1

# Only v1 (not recommended)
#Protocol 1

# Listen port (the IANA registered port number for ssh is 22)
Port 22

# The default listen address is all interfaces, this may need to be changed
# if you wish to restrict the interfaces sshd listens on for a multi homed host.
# Multiple ListenAddress entries are allowed.

# IPv4 only
#ListenAddress 0.0.0.0
# IPv4 & IPv6
ListenAddress ::

# If port forwarding is enabled (default), specify if the server can bind to
# INADDR_ANY. 
# This allows the local port forwarding to work when connections are received
# from any remote host.
GatewayPorts no

# X11 tunneling options
X11Forwarding yes
X11DisplayOffset 10
X11UseLocalhost yes

# The maximum number of concurrent unauthenticated connections to sshd.
# start:rate:full see sshd(1) for more information.
# The default is 10 unauthenticated clients.
#MaxStartups 10:30:60

# Banner to be printed before authentication starts.
#Banner /etc/issue

# Should sshd print the /etc/motd file and check for mail.
# On Solaris it is assumed that the login shell will do these (eg /etc/profile).
PrintMotd no

# KeepAlive specifies whether keep alive messages are sent to the client.
# See sshd(1) for detailed description of what this means.
# Note that the client may also be sending keep alive messages to the server.
KeepAlive yes

# Syslog facility and level 
SyslogFacility auth
LogLevel info

#
# Authentication configuration
# 

# Host private key files
# Must be on a local disk and readable only by the root user (root:sys 600).
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key

# Length of the server key
# Default 768, Minimum 512
ServerKeyBits 768

# sshd regenerates the key every KeyRegenerationInterval seconds.
# The key is never stored anywhere except the memory of sshd.
# The default is 1 hour (3600 seconds).
KeyRegenerationInterval 3600

# Ensure secure permissions on users .ssh directory.
StrictModes yes

# Length of time in seconds before a client that hasn't completed
# authentication is disconnected.
# Default is 600 seconds. 0 means no time limit.
LoginGraceTime 600

# Maximum number of retries for authentication
# Default is 6. Default (if unset) for MaxAuthTriesLog is MaxAuthTries / 2
MaxAuthTries	6
MaxAuthTriesLog	3

# Are logins to accounts with empty passwords allowed.
# If PermitEmptyPasswords is no, pass PAM_DISALLOW_NULL_AUTHTOK 
# to pam_authenticate(3PAM).
PermitEmptyPasswords no

# To disable tunneled clear text passwords, change PasswordAuthentication to no.
PasswordAuthentication yes

# Use PAM via keyboard interactive method for authentication.
# Depending on the setup of pam.conf(4) this may allow tunneled clear text
# passwords even when PasswordAuthentication is set to no. This is dependent
# on what the individual modules request and is out of the control of sshd
# or the protocol.
PAMAuthenticationViaKBDInt yes

# Are root logins permitted using sshd.
# Note that sshd uses pam_authenticate(3PAM) so the root (or any other) user
# maybe denied access by a PAM module regardless of this setting.
# Valid options are yes, without-password, no.
PermitRootLogin no

# sftp subsystem
Subsystem	sftp	internal-sftp


# SSH protocol v1 specific options
#
# The following options only apply to the v1 protocol and provide
# some form of backwards compatibility with the very weak security
# of /usr/bin/rsh.  Their use is not recommended and the functionality
# will be removed when support for v1 protocol is removed.

# Should sshd use .rhosts and .shosts for password less authentication.
IgnoreRhosts yes
RhostsAuthentication no

# Rhosts RSA Authentication
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts.
# If the user on the client side is not root then this won't work on
# Solaris since /usr/bin/ssh is not installed setuid.
RhostsRSAAuthentication no

# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication.
#IgnoreUserKnownHosts yes

# Is pure RSA authentication allowed.
# Default is yes
RSAAuthentication yes

# Example of overriding settings on a per-user basis
#Match User anoncvs
#	X11Forwarding no
#	AllowTcpForwarding no


--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)
Content-type: text/plain; name=sshd_config.orig
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.orig

#
# Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
# Use is subject to license terms.
#
# Configuration file for sshd(1m) (see also sshd_config(4))

# Protocol versions supported
#
# The sshd shipped in this release of Solaris has support for major versions
# 1 and 2.  It is recommended due to security weaknesses in the v1 protocol
# that sites run only v2 if possible. Support for v1 is provided to help sites
# with existing ssh v1 clients/servers to transition. 
# Support for v1 may not be available in a future release of Solaris.
#
# To enable support for v1 an RSA1 key must be created with ssh-keygen(1).
# RSA and DSA keys for protocol v2 are created by /etc/init.d/sshd if they
# do not already exist, RSA1 keys for protocol v1 are not automatically created.

# Uncomment ONLY ONE of the following Protocol statements.

# Only v2 (recommended)
Protocol 2

# Both v1 and v2 (not recommended)
#Protocol 2,1

# Only v1 (not recommended)
#Protocol 1

# Listen port (the IANA registered port number for ssh is 22)
Port 22

# The default listen address is all interfaces, this may need to be changed
# if you wish to restrict the interfaces sshd listens on for a multi homed host.
# Multiple ListenAddress entries are allowed.

# IPv4 only
#ListenAddress 0.0.0.0
# IPv4 & IPv6
ListenAddress ::

# If port forwarding is enabled (default), specify if the server can bind to
# INADDR_ANY. 
# This allows the local port forwarding to work when connections are received
# from any remote host.
GatewayPorts no

# X11 tunneling options
X11Forwarding yes
X11DisplayOffset 10
X11UseLocalhost yes

# The maximum number of concurrent unauthenticated connections to sshd.
# start:rate:full see sshd(1) for more information.
# The default is 10 unauthenticated clients.
#MaxStartups 10:30:60

# Banner to be printed before authentication starts.
#Banner /etc/issue

# Should sshd print the /etc/motd file and check for mail.
# On Solaris it is assumed that the login shell will do these (eg /etc/profile).
PrintMotd no

# KeepAlive specifies whether keep alive messages are sent to the client.
# See sshd(1) for detailed description of what this means.
# Note that the client may also be sending keep alive messages to the server.
KeepAlive yes

# Syslog facility and level 
SyslogFacility auth
LogLevel info

#
# Authentication configuration
# 

# Host private key files
# Must be on a local disk and readable only by the root user (root:sys 600).
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_dsa_key

# Length of the server key
# Default 768, Minimum 512
ServerKeyBits 768

# sshd regenerates the key every KeyRegenerationInterval seconds.
# The key is never stored anywhere except the memory of sshd.
# The default is 1 hour (3600 seconds).
KeyRegenerationInterval 3600

# Ensure secure permissions on users .ssh directory.
StrictModes yes

# Length of time in seconds before a client that hasn't completed
# authentication is disconnected.
# Default is 600 seconds. 0 means no time limit.
LoginGraceTime 600

# Maximum number of retries for authentication
# Default is 6. Default (if unset) for MaxAuthTriesLog is MaxAuthTries / 2
MaxAuthTries	6
MaxAuthTriesLog	3

# Are logins to accounts with empty passwords allowed.
# If PermitEmptyPasswords is no, pass PAM_DISALLOW_NULL_AUTHTOK 
# to pam_authenticate(3PAM).
PermitEmptyPasswords no

# To disable tunneled clear text passwords, change PasswordAuthentication to no.
PasswordAuthentication yes

# Use PAM via keyboard interactive method for authentication.
# Depending on the setup of pam.conf(4) this may allow tunneled clear text
# passwords even when PasswordAuthentication is set to no. This is dependent
# on what the individual modules request and is out of the control of sshd
# or the protocol.
PAMAuthenticationViaKBDInt yes

# Are root logins permitted using sshd.
# Note that sshd uses pam_authenticate(3PAM) so the root (or any other) user
# maybe denied access by a PAM module regardless of this setting.
# Valid options are yes, without-password, no.
PermitRootLogin no

# sftp subsystem
Subsystem	sftp	internal-sftp


# SSH protocol v1 specific options
#
# The following options only apply to the v1 protocol and provide
# some form of backwards compatibility with the very weak security
# of /usr/bin/rsh.  Their use is not recommended and the functionality
# will be removed when support for v1 protocol is removed.

# Should sshd use .rhosts and .shosts for password less authentication.
IgnoreRhosts yes
RhostsAuthentication no

# Rhosts RSA Authentication
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts.
# If the user on the client side is not root then this won't work on
# Solaris since /usr/bin/ssh is not installed setuid.
RhostsRSAAuthentication no

# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication.
#IgnoreUserKnownHosts yes

# Is pure RSA authentication allowed.
# Default is yes
RSAAuthentication yes


--Boundary_(ID_IUpjoNy+cqeeq0+6IODfZQ)--

From gdamore@sun.com Tue Oct  6 07:42:18 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n96EgH06007344
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 6 Oct 2009 07:42:17 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n96EgF4I049583
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 6 Oct 2009 08:42:17 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR300F09KUGZM00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.Com); Tue, 06 Oct 2009 07:42:16 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR300EDNKUFR820@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.Com); Tue,
 06 Oct 2009 07:42:15 -0700 (PDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n96EgFsX004254	for
 <PSARC-ext@Sun.Com>; Tue, 06 Oct 2009 07:42:15 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KR300500KN7WE00@fe-sfbay-10.sun.com> for PSARC-ext@Sun.Com
 (ORCPT PSARC-ext@Sun.Com); Tue, 06 Oct 2009 07:42:15 -0700 (PDT)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KR300M1CKUEW930@fe-sfbay-10.sun.com>; Tue,
 06 Oct 2009 07:42:14 -0700 (PDT)
Date: Tue, 06 Oct 2009 07:42:14 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: sshd match block option [PSARC/2009/531 FastTrack timeout
 10/13/2009]
In-reply-to: <200910061426.n96EQnFh021116@borg.sfbay>
Sender: Garrett.Damore@sun.com
To: Wyllys Ingersoll <wyllys@borg.sfbay.sun.com>
Cc: PSARC-ext@sun.com
Message-id: <4ACB5746.4020301@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200910061426.n96EQnFh021116@borg.sfbay>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 2375

+1 with one minor man page nit.  I think in your sshd_config.man, you 
should add ("!") after the sentence that ends "and negation operators."  
(Basically, you list the actual operators for wild cards, so you should 
be uniform and do so for negation as well.)

    - Garrett

Wyllys Ingersoll wrote:
> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 sshd match block option
>     1.2. Name of Document Author/Supplier:
> 	 Author:  HuieYing Lee
>     1.3  Date of This Document:
> 	06 October, 2009
> 4. Technical Description
> 1. Introduction
>
>    1.1. Project/Component Working Name:
>
>         The Match conditional block option for SunSSH server
>         
>    1.2. Name of Document Author/Supplier:
>
>         HuieYing Lee
>         
>    1.3. Date of This Document:
>
>         Oct 05 2009
>
> 4. Technical Description:
>
>    The goal of this project is to implement the Match conditional block
>    feature according to how OpenSSH implemented it in the 5.2p1 version
>    (released 2009-02-22). This feature enables a customer to specify
>    SSH server configuration options based on user, group, hostname, or
>    address.
>
>    This project introduces a Match conditional block in the sshd_config file,
>    the SunSSH server configuration file. If all of the criteria on the Match
>    line are satisfied, the keywords on the following lines override those
>    set in the global section of the configuration file, until either another
>    Match line or the end of the file.
>
>    The pertinent SunSSH OpenCR's are:
>      6655613 resync server's conditional Match block from OpenSSH
>      6871707 need new tests for ssh server's conditonal Match block feature
>              after putback of CR6655613
>      6881438 sshd_config(4) man page needs to be updated after putback of
>              CR6655613
>      6885011 ssh section in the system admin guide needs to be updated after
>              putback of CR6655613
>
>    Attached are the sshd_config file and man page changes.
> 	(see PSARC case materials directory)
>
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		ON
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
>
>   


From huie-ying.lee@sun.com Tue Oct  6 10:35:16 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n96HZCWC013449
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 6 Oct 2009 10:35:13 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n96HX5Fm029972;
	Wed, 7 Oct 2009 01:35:08 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR30090VSUCYU00@brm-avmta-1.central.sun.com>; Tue,
 06 Oct 2009 11:35:00 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR300M5ASUBHR80@brm-avmta-1.central.sun.com>; Tue,
 06 Oct 2009 11:34:59 -0600 (MDT)
Received: from [129.146.108.12] (comforter.SFBay.Sun.COM [129.146.108.12])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n96HYwid274806; Tue, 06 Oct 2009 10:34:58 -0700 (PDT)
Date: Tue, 06 Oct 2009 10:31:07 -0700
From: Huie-Ying Lee <huie-ying.lee@sun.com>
Subject: Re: sshd match block option [PSARC/2009/531 FastTrack timeout
 10/13/2009]
In-reply-to: <4ACB5746.4020301@sun.com>
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Wyllys Ingersoll <wyllys@borg.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <4ACB7EDB.4090303@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_RE1FBKzLYyITnf8o4QE7Yw)"
X-PMX-Version: 5.4.1.325704
References: <200910061426.n96EQnFh021116@borg.sfbay> <4ACB5746.4020301@sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090803)
Status: RO
Content-Length: 35824

This is a multi-part message in MIME format.

--Boundary_(ID_RE1FBKzLYyITnf8o4QE7Yw)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

On 10/06/09 07:42, Garrett D'Amore wrote:
> +1 with one minor man page nit.  I think in your sshd_config.man, you 
> should add ("!") after the sentence that ends "and negation 
> operators."  (Basically, you list the actual operators for wild cards, 
> so you should be uniform and do so for negation as well.)
>
>    - Garrett
>
Good point.   The sshd_config.man files  are updated and attached here.

Thanks,
Huie-Ying


> Wyllys Ingersoll wrote:
>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>> This information is Copyright 2009 Sun Microsystems
>> 1. Introduction
>>     1.1. Project/Component Working Name:
>>      sshd match block option
>>     1.2. Name of Document Author/Supplier:
>>      Author:  HuieYing Lee
>>     1.3  Date of This Document:
>>     06 October, 2009
>> 4. Technical Description
>> 1. Introduction
>>
>>    1.1. Project/Component Working Name:
>>
>>         The Match conditional block option for SunSSH server
>>            1.2. Name of Document Author/Supplier:
>>
>>         HuieYing Lee
>>            1.3. Date of This Document:
>>
>>         Oct 05 2009
>>
>> 4. Technical Description:
>>
>>    The goal of this project is to implement the Match conditional block
>>    feature according to how OpenSSH implemented it in the 5.2p1 version
>>    (released 2009-02-22). This feature enables a customer to specify
>>    SSH server configuration options based on user, group, hostname, or
>>    address.
>>
>>    This project introduces a Match conditional block in the 
>> sshd_config file,
>>    the SunSSH server configuration file. If all of the criteria on 
>> the Match
>>    line are satisfied, the keywords on the following lines override 
>> those
>>    set in the global section of the configuration file, until either 
>> another
>>    Match line or the end of the file.
>>
>>    The pertinent SunSSH OpenCR's are:
>>      6655613 resync server's conditional Match block from OpenSSH
>>      6871707 need new tests for ssh server's conditonal Match block 
>> feature
>>              after putback of CR6655613
>>      6881438 sshd_config(4) man page needs to be updated after 
>> putback of
>>              CR6655613
>>      6885011 ssh section in the system admin guide needs to be 
>> updated after
>>              putback of CR6655613
>>
>>    Attached are the sshd_config file and man page changes.
>>     (see PSARC case materials directory)
>>
>> 6. Resources and Schedule
>>     6.4. Steering Committee requested information
>>        6.4.1. Consolidation C-team Name:
>>         ON
>>     6.5. ARC review type: FastTrack
>>     6.6. ARC Exposure: open
>>
>>   
>


--Boundary_(ID_RE1FBKzLYyITnf8o4QE7Yw)
Content-type: text/plain; name=sshd_config.man.diff
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.diff

*** sshd_config.man.orig	Fri Sep 11 16:16:43 2009
--- sshd_config.man.new	Tue Oct  6 10:27:04 2009
***************
*** 500,505 ****
--- 500,557 ----
  	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.
  
  
+      Match
+ 
+          Introduces a conditional block.  If all of the criteria on the
+          Match line are satisfied, the keywords on the following lines
+          override those set in the global section of the config file,
+          until either another Match line or the end of the file.  Note 
+          that Match blocks must be located at the end of the file, after
+          all the global settings.
+ 
+          The arguments to Match are one or more criteria-pattern pairs.
+          The available criteria are User, Group, Host, and Address.  The
+          match patterns may consist of single entries or comma-separated
+          lists and may use the wildcard (Asterisk "*" and question mark "?")
+          and negation ("!") operators.
+ 
+          The patterns in a Host criteria should be hostname. The patterns
+          in an Address criteria should be IP address, which may
+          additionally contain addresses to match in CIDR address/masklen
+          format, e.g. ``192.0.2.0/24'' or ``2001:DB8::/32''.
+          Note that the mask length provided must be consistent with the
+          address - it is an error to specify a mask length that is too
+          long for the address or one with bits set in this host portion
+          of the address.  For example, ``192.0.2.0/33'' and ``192.0.2.0/8''
+          respectively.
+ 
+          Only a subset of keywords may be used on the lines following a
+          Match keyword.  Available keywords are AllowTcpForwarding,
+          Banner, ChrootDirectory, GatewayPorts, GSSAPIAuthentication,
+          HostbasedAuthentication, KbdInteractiveAuthentication,
+          MaxAuthTries, PasswordAuthentication, PermitEmptyPasswords,
+          PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication,
+          RSAAuthentication, X11DisplayOffset, X11Forwarding and
+          X11UseLocalhost.
+ 
+          Example 1: Disallow user "testuser" to use TCP forwarding
+          Match User testuser
+ 	     AllowTcpForwarding no
+ 
+          Example 2: Display a special banner for users not in the
+                     "staff" group
+          Match Group *,!staff
+              Banner /etc/banner.text
+ 
+          Example 3: Allow root login from host "rootallowed.example.com"
+          Match Host rootallowed.example.com
+             PermitRootLogin yes
+ 	     
+          Example 4: Allow anyone to use GatewayPorts from the local net
+          Match Address 192.168.0.0/24
+              GatewayPorts yes
+ 
+ 
       MaxStartups
  
  	 Specifies the maximum number of  concurrent  unauthenti-

--Boundary_(ID_RE1FBKzLYyITnf8o4QE7Yw)
Content-type: text/plain; name=sshd_config.man.new
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.new




File Formats					   sshd_config(4)



NAME
     sshd_config - sshd	configuration file

SYNOPSIS
     /etc/ssh/sshd_config


DESCRIPTION
     The  sshd(1M)   daemon   reads   configuration   data   from
     /etc/ssh/sshd_config  (or the file	specified with sshd -f on
     the command line).	The file  contains  keyword-value  pairs,
     one per line. A line starting with	a hash mark (#)	and empty
     lines are interpreted as comments.


     The sshd_config file supports the following keywords. Unless
     otherwise	noted,	keywords  and  their  arguments	are case-
     insensitive.

     AllowGroups

	 This keyword can be followed by a number of group names,
	 separated by spaces. If specified, login is allowed only
	 for users whose primary  group	 or  supplementary  group
	 list matches one of the patterns. Asterisk (*)	and ques-
	 tion mark (?) can be used as wildcards	in the	patterns.
	 Only  group names are valid; a	numerical group	ID is not
	 recognized. By	default, login is allowed  regardless  of
	 the primary group.


     AllowTcpForwarding

	 Specifies  whether  TCP  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  TCP  forwarding	does  not
	 improve security unless  users	 are  also  denied  shell
	 access, as they can always install their own forwarders.


     AllowUsers

	 This keyword can be followed by a number of user  names,
	 separated by spaces. If specified, login is allowed only
	 for user names	that match one of the patterns.	 Asterisk
	 (*)  and  question  mark (?) can be used as wildcards in
	 the patterns. Only user names	are  valid;  a	numerical
	 user  ID  is not recognized. By default login is allowed
	 regardless of the user	name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, restricting logins
	 to particular users from particular hosts.



SunOS 5.11	    Last change: 26 Mar	2009			1






File Formats					   sshd_config(4)



     AuthorizedKeysFile

	 Specifies the file that contains the  public  keys  that
	 can  be used for user authentication. AuthorizedKeysFile
	 can contain tokens of the form	%T, which are substituted
	 during	 connection  set-up.  The  following  tokens  are
	 defined: %% is	replaced by a literal %, %h  is	 replaced
	 by  the  home	directory of the user being authenticated
	 and %u	is replaced by the username of that  user.  After
	 expansion, AuthorizedKeysFile is taken	to be an absolute
	 path or one relative to the user's home  directory.  The
	 default is .ssh/authorized_keys.


     Banner

	 In some jurisdictions,	sending	a warning message  before
	 authentication	can be relevant	for getting legal protec-
	 tion. The contents of the specified file are sent to the
	 remote	 user  before  authentication  is  allowed.  This
	 option	is only	available  for	protocol  version  2.  By
	 default, no banner is displayed.


     ChrootDirectory

	 Specifies a path to chroot(2) to  after  authentication.
	 This  path,  and  all its components, must be root-owned
	 directories that are not writable by any other	 user  or
	 group.

	 The server always tries to change  to	the  user's  home
	 directory  locally  under the chrooted	environment but	a
	 failure to do so is not considered an	error.	In  addi-
	 tion,	the  path might	contain	the following tokens that
	 are expanded at runtime once  the  connecting	user  has
	 been authenticated: %%	is replaced by a literal %, %h is
	 replaced by the home directory	of the user being authen-
	 ticated,  and	%u  is	replaced  by the username of that
	 user.

	 The ChrootDirectory must contain the necessary	files and
	 directories  to  support  the	user's	session.  For  an
	 interactive SSH session this requires at least	a  user's
	 shell,	 shared	 libraries  needed  by the shell, dynamic
	 linker, and possibly basic  /dev  nodes  such	as  null,
	 zero,	stdin, stdout, stderr, random, and tty.	Addition-
	 ally, terminal	databases are needed for screen	 oriented
	 applications. For file	transfer sessions using	sftp with
	 the SSH protocol version 2, no	additional  configuration
	 of  the  environment is necessary if the in-process sftp
	 server	is used. See Subsystem for details.



SunOS 5.11	    Last change: 26 Mar	2009			2






File Formats					   sshd_config(4)



	 The default is	not to chroot(2).


     Ciphers

	 Specifies the ciphers allowed for  protocol  version  2.
	 Cipher	ordering on the	server side is not relevant. Mul-
	 tiple ciphers must be comma separated.

	 Valid ciphers are: aes128-ctr,	 aes192-ctr,  aes256-ctr,
	 aes128-cbc, aes192-cbc, aes256-cbc, arcfour, arcfour128,
	 arcfour256, 3des-cbc, and blowfish-cbc.

	 The default cipher list is:

	   aes128-ctr,aes192-ctr,aes256-ctr,arcfour128,
	   arcfour256,arcfour


	 Using CBC modes on the	server side  is	 not  recommended
	 due  to potential security issues in connection with the
	 SSH protocol version 2.


     ClientAliveCountMax

	 Sets the number of client alive  messages,  (see  Clien-
	 tAliveInterval), that can be sent without sshd	receiving
	 any messages back from	the client. If this threshold  is
	 reached while client alive messages are being sent, sshd
	 disconnects the client, terminating the session. The use
	 of   client   alive  messages	is  very  different  from
	 KeepAlive. The	client alive messages  are  sent  through
	 the  encrypted	 channel and therefore are not spoofable.
	 The TCP keepalive option enabled by KeepAlive is spoofa-
	 ble.  The  client  alive  mechanism  is  valuable when	a
	 client	or server depend on knowing when a connection has
	 become	inactive.

	 The default value is 3. If ClientAliveInterval	is set to
	 15,  and  ClientAliveCountMax	is  left  at the default,
	 unresponsive ssh clients are disconnected after approxi-
	 mately	45 seconds.


     ClientAliveInterval

	 Sets a	timeout	interval in seconds after  which,  if  no
	 data  has  been  received  from the client, sshd sends	a
	 message through  the  encrypted  channel  to  request	a
	 response  from	 the client. The default is 0, indicating
	 that these messages are not sent  to  the  client.  This



SunOS 5.11	    Last change: 26 Mar	2009			3






File Formats					   sshd_config(4)



	 option	applies	only to	protocol version 2.


     Compression

	 Controls whether the server allows the	client	to  nego-
	 tiate the use of compression. The default is yes.


     DenyGroups

	 Can be	followed by a number of	group names, separated by
	 spaces.  Users	 whose	primary	 group matches one of the
	 patterns are not allowed to log  in.  Asterisk	 (*)  and
	 question  mark	 (?) can be used as wildcards in the pat-
	 terns.	Only group names are valid; a numerical	group  ID
	 is  not recognized. By	default, login is allowed regard-
	 less of the primary group.


     DenyUsers

	 Can be	followed by a number of	user names, separated  by
	 spaces.  Login	 is  disallowed	for user names that match
	 one of	the patterns. Asterisk (*) and question	mark  (?)
	 can  be  used	as  wildcards  in the patterns.	Only user
	 names are valid; a numerical user ID is not  recognized.
	 By  default,  login  is  allowed  regardless of the user
	 name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, disallowing logins
	 to particular users from particular hosts.


     GatewayPorts

	 Specifies whether remote hosts	are allowed to connect to
	 ports	forwarded  for the client. By default, sshd binds
	 remote	port forwardings to the	 loopback  address.  This
	 prevents other	remote hosts from connecting to	forwarded
	 ports.	GatewayPorts can be used  to  specify  that  sshd
	 should	 bind  remote  port  forwardings  to the wildcard
	 address, thus allowing	remote hosts to	connect	 to  for-
	 warded	ports.

	 The argument can be no	to force remote	port  forwardings
	 to  be	 available  to	the local host only, yes to force
	 remote	port forwardings to bind to the	wildcard address,
	 or  clientspecified  to  allow	 the client to select the
	 address to which the forwarding is bound. The default is
	 no. See also RemoteForward in ssh_config(4).



SunOS 5.11	    Last change: 26 Mar	2009			4






File Formats					   sshd_config(4)



     GSSAPIAuthentication

	 Enables/disables  GSS-API   user   authentication.   The
	 default is yes.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIKeyExchange

	 Enables/disables  GSS-API-authenticated  key  exchanges.
	 The default is	yes.

	 This option also enables  the	use  of	 the  GSS-API  to
	 authenticate  the user	to server after	the key	exchange.
	 GSS-API key exchange  can  succeed  but  the  subsequent
	 authentication	using the GSS-API fail if the server does
	 not authorize the user's GSS principal	name to	the  tar-
	 get user account.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIStoreDelegatedCredentials

	 Enables/disables the use of  delegated	 GSS-API  creden-
	 tials on the server-side. The default is yes.

	 Specifically, this  option,  when  enabled,  causes  the
	 server	 to  store  delegated  GSS-API credentials in the
	 user's	default	GSS-API	credential store (which	 for  the
	 Kerberos V mechanism means /tmp/krb5cc_<uid>).

	 Note -

	   sshd	does not take any  steps  to  explicitly  destroy
	   stored  delegated  GSS-API credentials upon logout. It
	   is  the  responsibility  of	PAM  modules  to  destroy
	   credentials associated with a session.


     HostbasedAuthentication

	 Specifies whether  to	try  rhosts-based  authentication
	 with public key authentication. The argument must be yes
	 or no.	 The  default  is  no.	This  option  applies  to



SunOS 5.11	    Last change: 26 Mar	2009			5






File Formats					   sshd_config(4)



	 protocol  version  2 only and is similar to RhostsRSAAu-
	 thentication. See sshd(1M) for	guidelines on setting  up
	 host-based authentication.


     HostbasedUsesNameFromPacketOnly

	 Controls which	hostname is searched  for  in  the  files
	 ~/.shosts,  /etc/shosts.equiv,	 and /etc/hosts.equiv. If
	 this parameter	is set to yes, the server uses	the  name
	 the  client  claimed  for  itself  and	 signed	with that
	 host's	key. If	set to no, the default,	the  server  uses
	 the name to which the client's	IP address resolves.

	 Setting this parameter	to no disables host-based authen-
	 tication  when	 using NAT or when the client gets to the
	 server	indirectly through a port-forwarding firewall.


     HostKey

	 Specifies the file containing the private host	key  used
	 by  SSH. The default is /etc/ssh/ssh_host_key for proto-
	 col  version  1,   and	  /etc/ssh/ssh_host_rsa_key   and
	 /etc/ssh/ssh_host_dsa_key  for	 protocol version 2. sshd
	 refuses to use	a file if it  is  group/world-accessible.
	 It  is	 possible  to  have multiple host key files. rsa1
	 keys are used for version 1 and dsa or	rsa are	used  for
	 version 2 of the SSH protocol.


     IgnoreRhosts

	 Specifies that	.rhosts	and .shosts files are not used in
	 authentication.  /etc/hosts.equiv  and	/etc/shosts.equiv
	 are still used.  The  default	is  yes.  This	parameter
	 applies to both protocol versions 1 and 2.


     IgnoreUserKnownHosts

	 Specifies  whether  sshd  should   ignore   the   user's
	 $HOME/.ssh/known_hosts	 during	 RhostsRSAAuthentication.
	 The default is	no. This parameter applies to both proto-
	 col versions 1	and 2.


     KbdInteractiveAuthentication

	 Specifies  whether  authentication  by	 means	 of   the
	 "keyboard-interactive"	 authentication	 method	(and PAM)
	 is allowed. Defaults to yes. (Deprecated: this	parameter



SunOS 5.11	    Last change: 26 Mar	2009			6






File Formats					   sshd_config(4)



	 can only be set to yes.)


     KeepAlive

	 Specifies whether the system should send keepalive  mes-
	 sages	to the other side. If they are sent, death of the
	 connection or crash of	one of the machines  is	 properly
	 noticed. However, this	means that connections die if the
	 route is down temporarily, which can be an annoyance. On
	 the other hand, if keepalives are not sent, sessions can
	 hang indefinitely on the server, leaving ghost	users and
	 consuming server resources.

	 The default is	yes (to	send keepalives), and the  server
	 notices  if  the  network  goes  down or the client host
	 reboots. This avoids infinitely hanging sessions.

	 To disable keepalives,	the value should be set	to no  in
	 both the server and the client	configuration files.


     KeyRegenerationInterval

	 In protocol version  1,  the  ephemeral  server  key  is
	 automatically regenerated after this many seconds (if it
	 has been  used).  The	purpose	 of  regeneration  is  to
	 prevent  decrypting  captured sessions	by later breaking
	 into the machine and stealing the keys. The key is never
	 stored	 anywhere.  If	the  value is 0, the key is never
	 regenerated. The default is 3600 (seconds).


     ListenAddress

	 Specifies what	local address sshd should listen on.  The
	 following forms can be	used:

	   ListenAddress host|IPv4_addr|IPv6_addr
	   ListenAddress host|IPv4_addr:port
	   ListenAddress [host|IPv6_addr]:port

	 If port is not	specified, sshd	listens	 on  the  address
	 and  all prior	Port options specified.	The default is to
	 listen	on all local  addresses.  Multiple  ListenAddress
	 options  are  permitted.  Additionally, any Port options
	 must  precede	this  option   for   non-port	qualified
	 addresses.

	 The default is	to listen on all local addresses.  Multi-
	 ple  options  of  this	type are permitted. Additionally,
	 the Ports options must	precede	this option.



SunOS 5.11	    Last change: 26 Mar	2009			7






File Formats					   sshd_config(4)



     LoginGraceTime

	 The server disconnects	after this time	(in  seconds)  if
	 the user has not successfully logged in. If the value is
	 0, there is no	time limit. The	default	is 120 (seconds).


     LogLevel

	 Gives the verbosity level that	is used	when logging mes-
	 sages	from sshd. The possible	values are: QUIET, FATAL,
	 ERROR,	INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3.
	 The  default  is  INFO.  DEBUG2  and DEBUG3 each specify
	 higher	levels of debugging output.  Logging  with  level
	 DEBUG	violates  the  privacy of users	and is not recom-
	 mended.


     LookupClientHostnames

	 Specifies whether or not to lookup the	names of client's
	 addresses. Defaults to	yes.


     MACs

	 Specifies  the	 available  MAC	 (message  authentication
	 code)	algorithms. The	MAC algorithm is used in protocol
	 version 2 for data integrity protection. Multiple  algo-
	 rithms	 must  be  comma-separated.  The default is hmac-
	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.


     Match

         Introduces a conditional block.  If all of the criteria on the
         Match line are satisfied, the keywords on the following lines
         override those set in the global section of the config file,
         until either another Match line or the end of the file.  Note 
         that Match blocks must be located at the end of the file, after
         all the global settings.

         The arguments to Match are one or more criteria-pattern pairs.
         The available criteria are User, Group, Host, and Address.  The
         match patterns may consist of single entries or comma-separated
         lists and may use the wildcard (Asterisk "*" and question mark "?")
         and negation ("!") operators.

         The patterns in a Host criteria should be hostname. The patterns
         in an Address criteria should be IP address, which may
         additionally contain addresses to match in CIDR address/masklen
         format, e.g. ``192.0.2.0/24'' or ``2001:DB8::/32''.
         Note that the mask length provided must be consistent with the
         address - it is an error to specify a mask length that is too
         long for the address or one with bits set in this host portion
         of the address.  For example, ``192.0.2.0/33'' and ``192.0.2.0/8''
         respectively.

         Only a subset of keywords may be used on the lines following a
         Match keyword.  Available keywords are AllowTcpForwarding,
         Banner, ChrootDirectory, GatewayPorts, GSSAPIAuthentication,
         HostbasedAuthentication, KbdInteractiveAuthentication,
         MaxAuthTries, PasswordAuthentication, PermitEmptyPasswords,
         PermitRootLogin, PubkeyAuthentication, RhostsRSAAuthentication,
         RSAAuthentication, X11DisplayOffset, X11Forwarding and
         X11UseLocalhost.

         Example 1: Disallow user "testuser" to use TCP forwarding
         Match User testuser
	     AllowTcpForwarding no

         Example 2: Display a special banner for users not in the
                    "staff" group
         Match Group *,!staff
             Banner /etc/banner.text

         Example 3: Allow root login from host "rootallowed.example.com"
         Match Host rootallowed.example.com
            PermitRootLogin yes
	     
         Example 4: Allow anyone to use GatewayPorts from the local net
         Match Address 192.168.0.0/24
             GatewayPorts yes


     MaxStartups

	 Specifies the maximum number of  concurrent  unauthenti-
	 cated connections to the sshd daemon. Additional connec-
	 tions are dropped until authentication	succeeds  or  the
	 LoginGraceTime	 expires for a connection. The default is
	 10.

	 Alternatively,	random	early  drop  can  be  enabled  by
	 specifying	the    three	colon-separated	   values
	 start:rate:full (for example,	10:30:60).  Referring  to
	 this  example,	 sshd  refuse  connection attempts with	a
	 probability of	rate/100 (30% in our  example)	if  there
	 are  currently	10 (from the start field) unauthenticated
	 connections. The probability increases	linearly and  all
	 connection  attempts  are refused if the number of unau-
	 thenticated connections reaches full (60  in  our  exam-
	 ple).




SunOS 5.11	    Last change: 26 Mar	2009			8






File Formats					   sshd_config(4)



     PasswordAuthentication

	 Specifies whether password  authentication  is	 allowed.
	 The default is	yes. This option applies to both protocol
	 versions 1 and	2.


     PermitEmptyPasswords

	 When password or keyboard-interactive authentication  is
	 allowed, it specifies whether the server allows login to
	 accounts with empty password strings.

	 If not	set then the /etc/default/login	PASSREQ	value  is
	 used instead.

	 PASSREQ=no is equivalent  to  PermitEmptyPasswords  yes.
	 PASSREQ=yes is	equivalent to PermitEmptyPasswords no. If
	 neither PermitEmptyPasswords  or  PASSREQ  are	 set  the
	 default is no.


     PermitRootLogin

	 Specifies whether the root can	log in using ssh(1).  The
	 argument   must   be	yes,   without-password,  forced-
	 commands-only,	or no. without-password	means  that  root
	 cannot	  be   authenticated   using  the  "password"  or
	 "keyboard-interactive"	 methods  (see	 description   of
	 KbdInteractiveAuthentication).	     forced-commands-only
	 means that authentication is allowed only for	publickey
	 (for  SSHv2, or RSA, for SSHv1) and only if the matching
	 authorized_keys  entry	 for  root  has	 a  command=<cmd>
	 option.

	 In Solaris, the  default  /etc/ssh/sshd_config	 file  is
	 shipped  with PermitRootLogin set to no. If unset by the
	 administrator,	   then	   CONSOLE     parameter     from
	 /etc/default/login  supplies  the  default value as fol-
	 lows: if the CONSOLE parameter	is not commented out  (it
	 can  even  be empty, that is, "CONSOLE="), then without-
	 password is used as default value. If	CONSOLE	 is  com-
	 mented	out, then the default for PermitRootLogin is yes.

	 The without-password and  forced-commands-only	 settings
	 are  useful for, for example, performing remote adminis-
	 tration  and  backups	using  trusted	public	keys  for
	 authentication	 of  the  remote client, without allowing
	 access	to the root account using passwords.






SunOS 5.11	    Last change: 26 Mar	2009			9






File Formats					   sshd_config(4)



     PermitUserEnvironment

	 Specifies whether a  user's  ~/.ssh/environment  on  the
	 server	 side  and  environment	 options  in  the Author-
	 izedKeysFile file are processed by sshd. The default  is
	 no.  Enabling environment processing can enable users to
	 bypass	access restrictions in some configurations  using
	 mechanisms such as LD_PRELOAD.

	 Environment setting from a  relevant  entry  in  Author-
	 izedKeysFile  file  is	 processed  only  if the user was
	 authenticated	using  the  public   key   authentication
	 method.  Of  the two files used, values of variables set
	 in ~/.ssh/environment are of higher priority.


     PidFile

	 Allows	  you	 to    specify	  an	alternative    to
	 /var/run/sshd.pid,  the default file for storing the PID
	 of the	sshd listening for connections.	See sshd(1M).


     Port

	 Specifies the port number  that  sshd	listens	 on.  The
	 default is 22.	Multiple options of this type are permit-
	 ted. See also ListenAddress.


     PrintLastLog

	 Specifies whether sshd	should display the date	and  time
	 when the user last logged in. The default is yes.


     PrintMotd

	 Specifies whether sshd	should display	the  contents  of
	 /etc/motd  when  a  user logs in interactively. (On some
	 systems it is also displayed by the  shell  or	 a  shell
	 startup file, such as /etc/profile.) The default is yes.


     Protocol

	 Specifies the protocol	versions sshd should  support  in
	 order	of  preference.	 The possible values are 1 and 2.
	 Multiple versions must	be comma-separated.  The  default
	 is  2,1.  This	 means that ssh	tries version 2	and falls
	 back to version 1 if version 2	is not available.




SunOS 5.11	    Last change: 26 Mar	2009		       10






File Formats					   sshd_config(4)



     PubkeyAuthentication

	 Specifies whether public key authentication is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 2	only.


     RhostsAuthentication

	 Specifies  whether  authentication   using   rhosts   or
	 /etc/hosts.equiv  files  is  sufficient.  Normally, this
	 method	should not be permitted	because	it  is	insecure.
	 RhostsRSAAuthentication  should be used instead, because
	 it performs RSA-based host authentication in addition to
	 normal	 rhosts	 or  /etc/hosts.equiv authentication. The
	 default is no.	This parameter applies only  to	 protocol
	 version 1.


     RhostsRSAAuthentication

	 Specifies whether rhosts or /etc/hosts.equiv authentica-
	 tion together with successful RSA host	authentication is
	 allowed. The default is no. This parameter applies  only
	 to protocol version 1.


     RSAAuthentication

	 Specifies whether pure	RSA  authentication  is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 1	only.


     ServerKeyBits

	 Defines the number of bits  in	 the  ephemeral	 protocol
	 version  1 server key.	The minimum value is 512, and the
	 default is 768.


     StrictModes

	 Specifies whether sshd	should check file modes	and  own-
	 ership	 of  the  user's  files	and home directory before
	 accepting login.  This	 is  normally  desirable  because
	 novices  sometimes accidentally leave their directory or
	 files world-writable. The default is yes.


     Subsystem




SunOS 5.11	    Last change: 26 Mar	2009		       11






File Formats					   sshd_config(4)



	 Configures an external	subsystem (for	example,  a  file
	 transfer  daemon).  Arguments should be a subsystem name
	 and a command to execute  upon	 subsystem  request.  The
	 command   sftp-server(1M)   implements	  the  sftp  file
	 transfer subsystem.

	 Alternately, the name internal-sftp  implements  an  in-
	 process  sftp	server.	 This can simplify configurations
	 using ChrootDirectory to force	 a  different  filesystem
	 root on clients.

	 By default,  no  subsystems  are  defined.  This  option
	 applies to protocol version 2 only.


     SyslogFacility

	 Gives the facility code that is used when  logging  mes-
	 sages	from sshd. The possible	values are: DAEMON, USER,
	 AUTH, LOCAL0, LOCAL1, LOCAL2,	LOCAL3,	 LOCAL4,  LOCAL5,
	 LOCAL6, and LOCAL7. The default is AUTH.


     UseOpenSSLEngine

	 Specifies whether sshd	should use  the	 OpenSSL  PKCS#11
	 engine	 for  offloading  cryptographic	operations to the
	 Cryptographic Framework.  Cryptographic  operations  are
	 accelerated  according	 to the	available installed plug-
	 ins. When no suitable plug-ins	are present  this  option
	 does not have an effect. The default is yes.


     VerifyReverseMapping

	 Specifies whether sshd	should try to verify  the  remote
	 host  name and	check that the resolved	host name for the
	 remote	IP address maps	back to	the very same IP address.
	 (A  yes  setting means	"verify".) Setting this	parameter
	 to no can be useful where DNS servers might be	down  and
	 thus cause sshd to spend much time trying to resolve the
	 client's IP address to	a name.	This  feature  is  useful
	 for Internet-facing servers. The default is no.


     X11DisplayOffset

	 Specifies the first display number available for  sshd's
	 X11 forwarding. This prevents sshd from interfering with
	 real X11 servers. The default is 10.





SunOS 5.11	    Last change: 26 Mar	2009		       12






File Formats					   sshd_config(4)



     X11Forwarding

	 Specifies  whether  X11  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  X11  forwarding	does  not
	 improve security in any way, as users can always install
	 their own forwarders.

	 When X11 forwarding is	enabled, there can be  additional
	 exposure  to  the  server  and	to client displays if the
	 sshd proxy display is configured to listen on the  wild-
	 card address (see X11UseLocalhost). However, this is not
	 the default. Additionally, the	 authentication	 spoofing
	 and  authentication  data  verification and substitution
	 occur on the client side. The security	risk of	using X11
	 forwarding  is	 that the client's X11 display server can
	 be exposed to attack when the ssh client  requests  for-
	 warding    (see   the	 warnings   for	  ForwardX11   in
	 ssh_config(4)). A system administrator	who wants to pro-
	 tect  clients that expose themselves to attack	by unwit-
	 tingly	requesting X11 forwarding, should  specify  a  no
	 setting.

	 Disabling X11 forwarding does	not  prevent  users  from
	 forwarding  X11  traffic,  as	users  can always install
	 their own forwarders.


     X11UseLocalhost

	 Specifies whether sshd	should bind  the  X11  forwarding
	 server	 to  the  loopback  address  or	 to  the wildcard
	 address. By default, sshd binds the forwarding	server to
	 the  loopback	address	and sets the hostname part of the
	 DISPLAY environment variable to localhost. This prevents
	 remote	 hosts from connecting to the proxy display. How-
	 ever, some older X11 clients  might  not  function  with
	 this  configuration. X11UseLocalhost can be set to no to
	 specify that the forwarding server should  be	bound  to
	 the  wildcard	address.  The argument must be yes or no.
	 The default is	yes.


     XAuthLocation

	 Specifies the location	 of  the  xauth(1)  program.  The
	 default  is /usr/X11/bin/xauth	and sshd attempts to open
	 it when X11 forwarding	is enabled.


  Time Formats
     sshd command-line arguments and configuration  file  options
     that  specify  time can be	expressed using	a sequence of the



SunOS 5.11	    Last change: 26 Mar	2009		       13






File Formats					   sshd_config(4)



     form: time[qualifier,] where  time	 is  a	positive  integer
     value and qualifier is one	of the following:

     <none>    seconds


     s | S     seconds


     m | M     minutes


     h | H     hours


     d | D     days


     w |       weeks



     Each element of the sequence is added together to	calculate
     the total time value. For example:

     600      600 seconds (10 minutes)


     10m      10 minutes


     1h30m    1	hour, 30 minutes (90 minutes)


FILES
     /etc/ssh/sshd_config    Contains  configuration   data   for
			     sshd.  This  file should be writable
			     by	root only, but it is  recommended
			     (though  not  necessary)  that it be
			     world-readable.


ATTRIBUTES
     See attributes(5) for descriptions	of the	following  attri-
     butes:










SunOS 5.11	    Last change: 26 Mar	2009		       14






File Formats					   sshd_config(4)



     ____________________________________________________________
    |	    ATTRIBUTE TYPE	  |	  ATTRIBUTE VALUE	|
    |_____________________________|_____________________________|
    | Availability		  | SUNWsshu			|
    |_____________________________|_____________________________|
    | Interface	Stability	  | Uncommitted			|
    |_____________________________|_____________________________|


SEE ALSO
     login(1), sshd(1M), chroot(2), ssh_config(4), attributes(5),
     kerberos(5)

AUTHORS
     OpenSSH is	a derivative of	the original and free ssh  1.2.12
     release  by  Tatu	Ylonen.	 Aaron Campbell, Bob Beck, Markus
     Friedl, Niels Provos, Theo	de Raadt, and  Dug  Song  removed
     many  bugs,  re-added  recent features, and created OpenSSH.
     Markus Friedl contributed the support for SSH protocol  ver-
     sions  1.5	 and  2.0. Niels Provos	and Markus Friedl contri-
     buted support for privilege separation.


































SunOS 5.11	    Last change: 26 Mar	2009		       15




--Boundary_(ID_RE1FBKzLYyITnf8o4QE7Yw)--

From huie-ying.lee@sun.com Fri Nov  6 15:16:30 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nA6NGUIH009056
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 6 Nov 2009 15:16:30 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id nA6NG89u053196;
	Fri, 6 Nov 2009 16:16:29 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KSP00101NAZ3P00@nwk-avmta-2.sfbay.sun.com>; Fri,
 06 Nov 2009 15:16:11 -0800 (PST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KSP00GM8NAZ2190@nwk-avmta-2.sfbay.sun.com>; Fri,
 06 Nov 2009 15:16:11 -0800 (PST)
Received: from [129.146.108.12] (comforter.SFBay.Sun.COM [129.146.108.12])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nA6NGAT5628925; Fri, 06 Nov 2009 15:16:10 -0800 (PST)
Date: Fri, 06 Nov 2009 15:11:36 -0800
From: Huie-Ying Lee <huie-ying.lee@sun.com>
Subject: Re: sshd match block option [PSARC/2009/531 FastTrack timeout
 10/13/2009]
In-reply-to: <4ACB7EDB.4090303@sun.com>
To: PSARC-ext@sun.com
Cc: Wyllys Ingersoll <wyllys@borg.sfbay.sun.com>
Message-id: <4AF4AD28.8070302@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_1z6XaX/XS+7hxiEVL3Q3Cg)"
X-PMX-Version: 5.4.1.325704
References: <200910061426.n96EQnFh021116@borg.sfbay> <4ACB5746.4020301@sun.com>
 <4ACB7EDB.4090303@sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090803)
Status: RO
Content-Length: 36220

This is a multi-part message in MIME format.

--Boundary_(ID_1z6XaX/XS+7hxiEVL3Q3Cg)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

It was brought to my attention that the "MaxAuthTries" keyword is not 
currently supported in sshd_config file for SunSSH and the 
"KbdInteractiveAuthentication" keyword is deprecated.   Therefore, these 
two keywords will be removed from the Match supported
list in the new sshd_config man page.    The updated sshd_config.man 
page files are attached here.

Regards,
Huie-Ying


On 10/06/09 10:31, Huie-Ying Lee wrote:
> On 10/06/09 07:42, Garrett D'Amore wrote:
>> +1 with one minor man page nit.  I think in your sshd_config.man, you 
>> should add ("!") after the sentence that ends "and negation 
>> operators."  (Basically, you list the actual operators for wild 
>> cards, so you should be uniform and do so for negation as well.)
>>
>>    - Garrett
>>
> Good point.   The sshd_config.man files  are updated and attached here.
>
> Thanks,
> Huie-Ying
>
>
>> Wyllys Ingersoll wrote:
>>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>>> This information is Copyright 2009 Sun Microsystems
>>> 1. Introduction
>>>     1.1. Project/Component Working Name:
>>>      sshd match block option
>>>     1.2. Name of Document Author/Supplier:
>>>      Author:  HuieYing Lee
>>>     1.3  Date of This Document:
>>>     06 October, 2009
>>> 4. Technical Description
>>> 1. Introduction
>>>
>>>    1.1. Project/Component Working Name:
>>>
>>>         The Match conditional block option for SunSSH server
>>>            1.2. Name of Document Author/Supplier:
>>>
>>>         HuieYing Lee
>>>            1.3. Date of This Document:
>>>
>>>         Oct 05 2009
>>>
>>> 4. Technical Description:
>>>
>>>    The goal of this project is to implement the Match conditional block
>>>    feature according to how OpenSSH implemented it in the 5.2p1 version
>>>    (released 2009-02-22). This feature enables a customer to specify
>>>    SSH server configuration options based on user, group, hostname, or
>>>    address.
>>>
>>>    This project introduces a Match conditional block in the 
>>> sshd_config file,
>>>    the SunSSH server configuration file. If all of the criteria on 
>>> the Match
>>>    line are satisfied, the keywords on the following lines override 
>>> those
>>>    set in the global section of the configuration file, until either 
>>> another
>>>    Match line or the end of the file.
>>>
>>>    The pertinent SunSSH OpenCR's are:
>>>      6655613 resync server's conditional Match block from OpenSSH
>>>      6871707 need new tests for ssh server's conditonal Match block 
>>> feature
>>>              after putback of CR6655613
>>>      6881438 sshd_config(4) man page needs to be updated after 
>>> putback of
>>>              CR6655613
>>>      6885011 ssh section in the system admin guide needs to be 
>>> updated after
>>>              putback of CR6655613
>>>
>>>    Attached are the sshd_config file and man page changes.
>>>     (see PSARC case materials directory)
>>>
>>> 6. Resources and Schedule
>>>     6.4. Steering Committee requested information
>>>        6.4.1. Consolidation C-team Name:
>>>         ON
>>>     6.5. ARC review type: FastTrack
>>>     6.6. ARC Exposure: open
>>>
>>>   
>>


--Boundary_(ID_1z6XaX/XS+7hxiEVL3Q3Cg)
Content-type: text/plain; name=sshd_config.man.diff
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.diff

*** sshd_config.man.orig	Fri Sep 11 16:16:43 2009
--- sshd_config.man.new	Fri Nov  6 14:54:45 2009
***************
*** 500,505 ****
--- 500,556 ----
  	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.
  
  
+      Match
+ 
+          Introduces a conditional block.  If all of the criteria on the
+          Match line are satisfied, the keywords on the following lines
+          override those set in the global section of the config file,
+          until either another Match line or the end of the file.  Note 
+          that Match blocks must be located at the end of the file, after
+          all the global settings.
+ 
+          The arguments to Match are one or more criteria-pattern pairs.
+          The available criteria are User, Group, Host, and Address.  The
+          match patterns may consist of single entries or comma-separated
+          lists and may use the wildcard (Asterisk "*" and question mark "?")
+          and negation ("!") operators.
+ 
+          The patterns in a Host criteria should be hostname. The patterns
+          in an Address criteria should be IP address, which may
+          additionally contain addresses to match in CIDR address/masklen
+          format, e.g. ``192.0.2.0/24'' or ``2001:DB8::/32''.
+          Note that the mask length provided must be consistent with the
+          address - it is an error to specify a mask length that is too
+          long for the address or one with bits set in this host portion
+          of the address.  For example, ``192.0.2.0/33'' and ``192.0.2.0/8''
+          respectively.
+ 
+          Only a subset of keywords may be used on the lines following a
+          Match keyword.  Available keywords are AllowTcpForwarding,
+          Banner, ChrootDirectory, GatewayPorts, GSSAPIAuthentication,
+          HostbasedAuthentication, PasswordAuthentication,
+          PermitEmptyPasswords, PermitRootLogin, PubkeyAuthentication,
+          RhostsRSAAuthentication, RSAAuthentication, X11DisplayOffset,
+          X11Forwarding and X11UseLocalhost.
+ 
+          Example 1: Disallow user "testuser" to use TCP forwarding
+          Match User testuser
+ 	     AllowTcpForwarding no
+ 
+          Example 2: Display a special banner for users not in the
+                     "staff" group
+          Match Group *,!staff
+              Banner /etc/banner.text
+ 
+          Example 3: Allow root login from host "rootallowed.example.com"
+          Match Host rootallowed.example.com
+             PermitRootLogin yes
+ 	     
+          Example 4: Allow anyone to use GatewayPorts from the local net
+          Match Address 192.168.0.0/24
+              GatewayPorts yes
+ 
+ 
       MaxStartups
  
  	 Specifies the maximum number of  concurrent  unauthenti-

--Boundary_(ID_1z6XaX/XS+7hxiEVL3Q3Cg)
Content-type: text/plain; name=sshd_config.man.new
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=sshd_config.man.new




File Formats					   sshd_config(4)



NAME
     sshd_config - sshd	configuration file

SYNOPSIS
     /etc/ssh/sshd_config


DESCRIPTION
     The  sshd(1M)   daemon   reads   configuration   data   from
     /etc/ssh/sshd_config  (or the file	specified with sshd -f on
     the command line).	The file  contains  keyword-value  pairs,
     one per line. A line starting with	a hash mark (#)	and empty
     lines are interpreted as comments.


     The sshd_config file supports the following keywords. Unless
     otherwise	noted,	keywords  and  their  arguments	are case-
     insensitive.

     AllowGroups

	 This keyword can be followed by a number of group names,
	 separated by spaces. If specified, login is allowed only
	 for users whose primary  group	 or  supplementary  group
	 list matches one of the patterns. Asterisk (*)	and ques-
	 tion mark (?) can be used as wildcards	in the	patterns.
	 Only  group names are valid; a	numerical group	ID is not
	 recognized. By	default, login is allowed  regardless  of
	 the primary group.


     AllowTcpForwarding

	 Specifies  whether  TCP  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  TCP  forwarding	does  not
	 improve security unless  users	 are  also  denied  shell
	 access, as they can always install their own forwarders.


     AllowUsers

	 This keyword can be followed by a number of user  names,
	 separated by spaces. If specified, login is allowed only
	 for user names	that match one of the patterns.	 Asterisk
	 (*)  and  question  mark (?) can be used as wildcards in
	 the patterns. Only user names	are  valid;  a	numerical
	 user  ID  is not recognized. By default login is allowed
	 regardless of the user	name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, restricting logins
	 to particular users from particular hosts.



SunOS 5.11	    Last change: 26 Mar	2009			1






File Formats					   sshd_config(4)



     AuthorizedKeysFile

	 Specifies the file that contains the  public  keys  that
	 can  be used for user authentication. AuthorizedKeysFile
	 can contain tokens of the form	%T, which are substituted
	 during	 connection  set-up.  The  following  tokens  are
	 defined: %% is	replaced by a literal %, %h  is	 replaced
	 by  the  home	directory of the user being authenticated
	 and %u	is replaced by the username of that  user.  After
	 expansion, AuthorizedKeysFile is taken	to be an absolute
	 path or one relative to the user's home  directory.  The
	 default is .ssh/authorized_keys.


     Banner

	 In some jurisdictions,	sending	a warning message  before
	 authentication	can be relevant	for getting legal protec-
	 tion. The contents of the specified file are sent to the
	 remote	 user  before  authentication  is  allowed.  This
	 option	is only	available  for	protocol  version  2.  By
	 default, no banner is displayed.


     ChrootDirectory

	 Specifies a path to chroot(2) to  after  authentication.
	 This  path,  and  all its components, must be root-owned
	 directories that are not writable by any other	 user  or
	 group.

	 The server always tries to change  to	the  user's  home
	 directory  locally  under the chrooted	environment but	a
	 failure to do so is not considered an	error.	In  addi-
	 tion,	the  path might	contain	the following tokens that
	 are expanded at runtime once  the  connecting	user  has
	 been authenticated: %%	is replaced by a literal %, %h is
	 replaced by the home directory	of the user being authen-
	 ticated,  and	%u  is	replaced  by the username of that
	 user.

	 The ChrootDirectory must contain the necessary	files and
	 directories  to  support  the	user's	session.  For  an
	 interactive SSH session this requires at least	a  user's
	 shell,	 shared	 libraries  needed  by the shell, dynamic
	 linker, and possibly basic  /dev  nodes  such	as  null,
	 zero,	stdin, stdout, stderr, random, and tty.	Addition-
	 ally, terminal	databases are needed for screen	 oriented
	 applications. For file	transfer sessions using	sftp with
	 the SSH protocol version 2, no	additional  configuration
	 of  the  environment is necessary if the in-process sftp
	 server	is used. See Subsystem for details.



SunOS 5.11	    Last change: 26 Mar	2009			2






File Formats					   sshd_config(4)



	 The default is	not to chroot(2).


     Ciphers

	 Specifies the ciphers allowed for  protocol  version  2.
	 Cipher	ordering on the	server side is not relevant. Mul-
	 tiple ciphers must be comma separated.

	 Valid ciphers are: aes128-ctr,	 aes192-ctr,  aes256-ctr,
	 aes128-cbc, aes192-cbc, aes256-cbc, arcfour, arcfour128,
	 arcfour256, 3des-cbc, and blowfish-cbc.

	 The default cipher list is:

	   aes128-ctr,aes192-ctr,aes256-ctr,arcfour128,
	   arcfour256,arcfour


	 Using CBC modes on the	server side  is	 not  recommended
	 due  to potential security issues in connection with the
	 SSH protocol version 2.


     ClientAliveCountMax

	 Sets the number of client alive  messages,  (see  Clien-
	 tAliveInterval), that can be sent without sshd	receiving
	 any messages back from	the client. If this threshold  is
	 reached while client alive messages are being sent, sshd
	 disconnects the client, terminating the session. The use
	 of   client   alive  messages	is  very  different  from
	 KeepAlive. The	client alive messages  are  sent  through
	 the  encrypted	 channel and therefore are not spoofable.
	 The TCP keepalive option enabled by KeepAlive is spoofa-
	 ble.  The  client  alive  mechanism  is  valuable when	a
	 client	or server depend on knowing when a connection has
	 become	inactive.

	 The default value is 3. If ClientAliveInterval	is set to
	 15,  and  ClientAliveCountMax	is  left  at the default,
	 unresponsive ssh clients are disconnected after approxi-
	 mately	45 seconds.


     ClientAliveInterval

	 Sets a	timeout	interval in seconds after  which,  if  no
	 data  has  been  received  from the client, sshd sends	a
	 message through  the  encrypted  channel  to  request	a
	 response  from	 the client. The default is 0, indicating
	 that these messages are not sent  to  the  client.  This



SunOS 5.11	    Last change: 26 Mar	2009			3






File Formats					   sshd_config(4)



	 option	applies	only to	protocol version 2.


     Compression

	 Controls whether the server allows the	client	to  nego-
	 tiate the use of compression. The default is yes.


     DenyGroups

	 Can be	followed by a number of	group names, separated by
	 spaces.  Users	 whose	primary	 group matches one of the
	 patterns are not allowed to log  in.  Asterisk	 (*)  and
	 question  mark	 (?) can be used as wildcards in the pat-
	 terns.	Only group names are valid; a numerical	group  ID
	 is  not recognized. By	default, login is allowed regard-
	 less of the primary group.


     DenyUsers

	 Can be	followed by a number of	user names, separated  by
	 spaces.  Login	 is  disallowed	for user names that match
	 one of	the patterns. Asterisk (*) and question	mark  (?)
	 can  be  used	as  wildcards  in the patterns.	Only user
	 names are valid; a numerical user ID is not  recognized.
	 By  default,  login  is  allowed  regardless of the user
	 name.

	 If a specified	pattern	takes  the  form  user@host  then
	 user and host are checked separately, disallowing logins
	 to particular users from particular hosts.


     GatewayPorts

	 Specifies whether remote hosts	are allowed to connect to
	 ports	forwarded  for the client. By default, sshd binds
	 remote	port forwardings to the	 loopback  address.  This
	 prevents other	remote hosts from connecting to	forwarded
	 ports.	GatewayPorts can be used  to  specify  that  sshd
	 should	 bind  remote  port  forwardings  to the wildcard
	 address, thus allowing	remote hosts to	connect	 to  for-
	 warded	ports.

	 The argument can be no	to force remote	port  forwardings
	 to  be	 available  to	the local host only, yes to force
	 remote	port forwardings to bind to the	wildcard address,
	 or  clientspecified  to  allow	 the client to select the
	 address to which the forwarding is bound. The default is
	 no. See also RemoteForward in ssh_config(4).



SunOS 5.11	    Last change: 26 Mar	2009			4






File Formats					   sshd_config(4)



     GSSAPIAuthentication

	 Enables/disables  GSS-API   user   authentication.   The
	 default is yes.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIKeyExchange

	 Enables/disables  GSS-API-authenticated  key  exchanges.
	 The default is	yes.

	 This option also enables  the	use  of	 the  GSS-API  to
	 authenticate  the user	to server after	the key	exchange.
	 GSS-API key exchange  can  succeed  but  the  subsequent
	 authentication	using the GSS-API fail if the server does
	 not authorize the user's GSS principal	name to	the  tar-
	 get user account.

	 Currently sshd	authorizes client user principals to user
	 accounts  as  follows:	if the principal name matches the
	 requested user	account, then the  principal  is  author-
	 ized. Otherwise, GSS-API authentication fails.


     GSSAPIStoreDelegatedCredentials

	 Enables/disables the use of  delegated	 GSS-API  creden-
	 tials on the server-side. The default is yes.

	 Specifically, this  option,  when  enabled,  causes  the
	 server	 to  store  delegated  GSS-API credentials in the
	 user's	default	GSS-API	credential store (which	 for  the
	 Kerberos V mechanism means /tmp/krb5cc_<uid>).

	 Note -

	   sshd	does not take any  steps  to  explicitly  destroy
	   stored  delegated  GSS-API credentials upon logout. It
	   is  the  responsibility  of	PAM  modules  to  destroy
	   credentials associated with a session.


     HostbasedAuthentication

	 Specifies whether  to	try  rhosts-based  authentication
	 with public key authentication. The argument must be yes
	 or no.	 The  default  is  no.	This  option  applies  to



SunOS 5.11	    Last change: 26 Mar	2009			5






File Formats					   sshd_config(4)



	 protocol  version  2 only and is similar to RhostsRSAAu-
	 thentication. See sshd(1M) for	guidelines on setting  up
	 host-based authentication.


     HostbasedUsesNameFromPacketOnly

	 Controls which	hostname is searched  for  in  the  files
	 ~/.shosts,  /etc/shosts.equiv,	 and /etc/hosts.equiv. If
	 this parameter	is set to yes, the server uses	the  name
	 the  client  claimed  for  itself  and	 signed	with that
	 host's	key. If	set to no, the default,	the  server  uses
	 the name to which the client's	IP address resolves.

	 Setting this parameter	to no disables host-based authen-
	 tication  when	 using NAT or when the client gets to the
	 server	indirectly through a port-forwarding firewall.


     HostKey

	 Specifies the file containing the private host	key  used
	 by  SSH. The default is /etc/ssh/ssh_host_key for proto-
	 col  version  1,   and	  /etc/ssh/ssh_host_rsa_key   and
	 /etc/ssh/ssh_host_dsa_key  for	 protocol version 2. sshd
	 refuses to use	a file if it  is  group/world-accessible.
	 It  is	 possible  to  have multiple host key files. rsa1
	 keys are used for version 1 and dsa or	rsa are	used  for
	 version 2 of the SSH protocol.


     IgnoreRhosts

	 Specifies that	.rhosts	and .shosts files are not used in
	 authentication.  /etc/hosts.equiv  and	/etc/shosts.equiv
	 are still used.  The  default	is  yes.  This	parameter
	 applies to both protocol versions 1 and 2.


     IgnoreUserKnownHosts

	 Specifies  whether  sshd  should   ignore   the   user's
	 $HOME/.ssh/known_hosts	 during	 RhostsRSAAuthentication.
	 The default is	no. This parameter applies to both proto-
	 col versions 1	and 2.


     KbdInteractiveAuthentication

	 Specifies  whether  authentication  by	 means	 of   the
	 "keyboard-interactive"	 authentication	 method	(and PAM)
	 is allowed. Defaults to yes. (Deprecated: this	parameter



SunOS 5.11	    Last change: 26 Mar	2009			6






File Formats					   sshd_config(4)



	 can only be set to yes.)


     KeepAlive

	 Specifies whether the system should send keepalive  mes-
	 sages	to the other side. If they are sent, death of the
	 connection or crash of	one of the machines  is	 properly
	 noticed. However, this	means that connections die if the
	 route is down temporarily, which can be an annoyance. On
	 the other hand, if keepalives are not sent, sessions can
	 hang indefinitely on the server, leaving ghost	users and
	 consuming server resources.

	 The default is	yes (to	send keepalives), and the  server
	 notices  if  the  network  goes  down or the client host
	 reboots. This avoids infinitely hanging sessions.

	 To disable keepalives,	the value should be set	to no  in
	 both the server and the client	configuration files.


     KeyRegenerationInterval

	 In protocol version  1,  the  ephemeral  server  key  is
	 automatically regenerated after this many seconds (if it
	 has been  used).  The	purpose	 of  regeneration  is  to
	 prevent  decrypting  captured sessions	by later breaking
	 into the machine and stealing the keys. The key is never
	 stored	 anywhere.  If	the  value is 0, the key is never
	 regenerated. The default is 3600 (seconds).


     ListenAddress

	 Specifies what	local address sshd should listen on.  The
	 following forms can be	used:

	   ListenAddress host|IPv4_addr|IPv6_addr
	   ListenAddress host|IPv4_addr:port
	   ListenAddress [host|IPv6_addr]:port

	 If port is not	specified, sshd	listens	 on  the  address
	 and  all prior	Port options specified.	The default is to
	 listen	on all local  addresses.  Multiple  ListenAddress
	 options  are  permitted.  Additionally, any Port options
	 must  precede	this  option   for   non-port	qualified
	 addresses.

	 The default is	to listen on all local addresses.  Multi-
	 ple  options  of  this	type are permitted. Additionally,
	 the Ports options must	precede	this option.



SunOS 5.11	    Last change: 26 Mar	2009			7






File Formats					   sshd_config(4)



     LoginGraceTime

	 The server disconnects	after this time	(in  seconds)  if
	 the user has not successfully logged in. If the value is
	 0, there is no	time limit. The	default	is 120 (seconds).


     LogLevel

	 Gives the verbosity level that	is used	when logging mes-
	 sages	from sshd. The possible	values are: QUIET, FATAL,
	 ERROR,	INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, and DEBUG3.
	 The  default  is  INFO.  DEBUG2  and DEBUG3 each specify
	 higher	levels of debugging output.  Logging  with  level
	 DEBUG	violates  the  privacy of users	and is not recom-
	 mended.


     LookupClientHostnames

	 Specifies whether or not to lookup the	names of client's
	 addresses. Defaults to	yes.


     MACs

	 Specifies  the	 available  MAC	 (message  authentication
	 code)	algorithms. The	MAC algorithm is used in protocol
	 version 2 for data integrity protection. Multiple  algo-
	 rithms	 must  be  comma-separated.  The default is hmac-
	 md5,hmac-sha1,hmac-sha1-96,hmac-md5-96.


     Match

         Introduces a conditional block.  If all of the criteria on the
         Match line are satisfied, the keywords on the following lines
         override those set in the global section of the config file,
         until either another Match line or the end of the file.  Note 
         that Match blocks must be located at the end of the file, after
         all the global settings.

         The arguments to Match are one or more criteria-pattern pairs.
         The available criteria are User, Group, Host, and Address.  The
         match patterns may consist of single entries or comma-separated
         lists and may use the wildcard (Asterisk "*" and question mark "?")
         and negation ("!") operators.

         The patterns in a Host criteria should be hostname. The patterns
         in an Address criteria should be IP address, which may
         additionally contain addresses to match in CIDR address/masklen
         format, e.g. ``192.0.2.0/24'' or ``2001:DB8::/32''.
         Note that the mask length provided must be consistent with the
         address - it is an error to specify a mask length that is too
         long for the address or one with bits set in this host portion
         of the address.  For example, ``192.0.2.0/33'' and ``192.0.2.0/8''
         respectively.

         Only a subset of keywords may be used on the lines following a
         Match keyword.  Available keywords are AllowTcpForwarding,
         Banner, ChrootDirectory, GatewayPorts, GSSAPIAuthentication,
         HostbasedAuthentication, PasswordAuthentication,
         PermitEmptyPasswords, PermitRootLogin, PubkeyAuthentication,
         RhostsRSAAuthentication, RSAAuthentication, X11DisplayOffset,
         X11Forwarding and X11UseLocalhost.

         Example 1: Disallow user "testuser" to use TCP forwarding
         Match User testuser
	     AllowTcpForwarding no

         Example 2: Display a special banner for users not in the
                    "staff" group
         Match Group *,!staff
             Banner /etc/banner.text

         Example 3: Allow root login from host "rootallowed.example.com"
         Match Host rootallowed.example.com
            PermitRootLogin yes
	     
         Example 4: Allow anyone to use GatewayPorts from the local net
         Match Address 192.168.0.0/24
             GatewayPorts yes


     MaxStartups

	 Specifies the maximum number of  concurrent  unauthenti-
	 cated connections to the sshd daemon. Additional connec-
	 tions are dropped until authentication	succeeds  or  the
	 LoginGraceTime	 expires for a connection. The default is
	 10.

	 Alternatively,	random	early  drop  can  be  enabled  by
	 specifying	the    three	colon-separated	   values
	 start:rate:full (for example,	10:30:60).  Referring  to
	 this  example,	 sshd  refuse  connection attempts with	a
	 probability of	rate/100 (30% in our  example)	if  there
	 are  currently	10 (from the start field) unauthenticated
	 connections. The probability increases	linearly and  all
	 connection  attempts  are refused if the number of unau-
	 thenticated connections reaches full (60  in  our  exam-
	 ple).




SunOS 5.11	    Last change: 26 Mar	2009			8






File Formats					   sshd_config(4)



     PasswordAuthentication

	 Specifies whether password  authentication  is	 allowed.
	 The default is	yes. This option applies to both protocol
	 versions 1 and	2.


     PermitEmptyPasswords

	 When password or keyboard-interactive authentication  is
	 allowed, it specifies whether the server allows login to
	 accounts with empty password strings.

	 If not	set then the /etc/default/login	PASSREQ	value  is
	 used instead.

	 PASSREQ=no is equivalent  to  PermitEmptyPasswords  yes.
	 PASSREQ=yes is	equivalent to PermitEmptyPasswords no. If
	 neither PermitEmptyPasswords  or  PASSREQ  are	 set  the
	 default is no.


     PermitRootLogin

	 Specifies whether the root can	log in using ssh(1).  The
	 argument   must   be	yes,   without-password,  forced-
	 commands-only,	or no. without-password	means  that  root
	 cannot	  be   authenticated   using  the  "password"  or
	 "keyboard-interactive"	 methods  (see	 description   of
	 KbdInteractiveAuthentication).	     forced-commands-only
	 means that authentication is allowed only for	publickey
	 (for  SSHv2, or RSA, for SSHv1) and only if the matching
	 authorized_keys  entry	 for  root  has	 a  command=<cmd>
	 option.

	 In Solaris, the  default  /etc/ssh/sshd_config	 file  is
	 shipped  with PermitRootLogin set to no. If unset by the
	 administrator,	   then	   CONSOLE     parameter     from
	 /etc/default/login  supplies  the  default value as fol-
	 lows: if the CONSOLE parameter	is not commented out  (it
	 can  even  be empty, that is, "CONSOLE="), then without-
	 password is used as default value. If	CONSOLE	 is  com-
	 mented	out, then the default for PermitRootLogin is yes.

	 The without-password and  forced-commands-only	 settings
	 are  useful for, for example, performing remote adminis-
	 tration  and  backups	using  trusted	public	keys  for
	 authentication	 of  the  remote client, without allowing
	 access	to the root account using passwords.






SunOS 5.11	    Last change: 26 Mar	2009			9






File Formats					   sshd_config(4)



     PermitUserEnvironment

	 Specifies whether a  user's  ~/.ssh/environment  on  the
	 server	 side  and  environment	 options  in  the Author-
	 izedKeysFile file are processed by sshd. The default  is
	 no.  Enabling environment processing can enable users to
	 bypass	access restrictions in some configurations  using
	 mechanisms such as LD_PRELOAD.

	 Environment setting from a  relevant  entry  in  Author-
	 izedKeysFile  file  is	 processed  only  if the user was
	 authenticated	using  the  public   key   authentication
	 method.  Of  the two files used, values of variables set
	 in ~/.ssh/environment are of higher priority.


     PidFile

	 Allows	  you	 to    specify	  an	alternative    to
	 /var/run/sshd.pid,  the default file for storing the PID
	 of the	sshd listening for connections.	See sshd(1M).


     Port

	 Specifies the port number  that  sshd	listens	 on.  The
	 default is 22.	Multiple options of this type are permit-
	 ted. See also ListenAddress.


     PrintLastLog

	 Specifies whether sshd	should display the date	and  time
	 when the user last logged in. The default is yes.


     PrintMotd

	 Specifies whether sshd	should display	the  contents  of
	 /etc/motd  when  a  user logs in interactively. (On some
	 systems it is also displayed by the  shell  or	 a  shell
	 startup file, such as /etc/profile.) The default is yes.


     Protocol

	 Specifies the protocol	versions sshd should  support  in
	 order	of  preference.	 The possible values are 1 and 2.
	 Multiple versions must	be comma-separated.  The  default
	 is  2,1.  This	 means that ssh	tries version 2	and falls
	 back to version 1 if version 2	is not available.




SunOS 5.11	    Last change: 26 Mar	2009		       10






File Formats					   sshd_config(4)



     PubkeyAuthentication

	 Specifies whether public key authentication is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 2	only.


     RhostsAuthentication

	 Specifies  whether  authentication   using   rhosts   or
	 /etc/hosts.equiv  files  is  sufficient.  Normally, this
	 method	should not be permitted	because	it  is	insecure.
	 RhostsRSAAuthentication  should be used instead, because
	 it performs RSA-based host authentication in addition to
	 normal	 rhosts	 or  /etc/hosts.equiv authentication. The
	 default is no.	This parameter applies only  to	 protocol
	 version 1.


     RhostsRSAAuthentication

	 Specifies whether rhosts or /etc/hosts.equiv authentica-
	 tion together with successful RSA host	authentication is
	 allowed. The default is no. This parameter applies  only
	 to protocol version 1.


     RSAAuthentication

	 Specifies whether pure	RSA  authentication  is	 allowed.
	 The default is	yes. This option applies to protocol ver-
	 sion 1	only.


     ServerKeyBits

	 Defines the number of bits  in	 the  ephemeral	 protocol
	 version  1 server key.	The minimum value is 512, and the
	 default is 768.


     StrictModes

	 Specifies whether sshd	should check file modes	and  own-
	 ership	 of  the  user's  files	and home directory before
	 accepting login.  This	 is  normally  desirable  because
	 novices  sometimes accidentally leave their directory or
	 files world-writable. The default is yes.


     Subsystem




SunOS 5.11	    Last change: 26 Mar	2009		       11






File Formats					   sshd_config(4)



	 Configures an external	subsystem (for	example,  a  file
	 transfer  daemon).  Arguments should be a subsystem name
	 and a command to execute  upon	 subsystem  request.  The
	 command   sftp-server(1M)   implements	  the  sftp  file
	 transfer subsystem.

	 Alternately, the name internal-sftp  implements  an  in-
	 process  sftp	server.	 This can simplify configurations
	 using ChrootDirectory to force	 a  different  filesystem
	 root on clients.

	 By default,  no  subsystems  are  defined.  This  option
	 applies to protocol version 2 only.


     SyslogFacility

	 Gives the facility code that is used when  logging  mes-
	 sages	from sshd. The possible	values are: DAEMON, USER,
	 AUTH, LOCAL0, LOCAL1, LOCAL2,	LOCAL3,	 LOCAL4,  LOCAL5,
	 LOCAL6, and LOCAL7. The default is AUTH.


     UseOpenSSLEngine

	 Specifies whether sshd	should use  the	 OpenSSL  PKCS#11
	 engine	 for  offloading  cryptographic	operations to the
	 Cryptographic Framework.  Cryptographic  operations  are
	 accelerated  according	 to the	available installed plug-
	 ins. When no suitable plug-ins	are present  this  option
	 does not have an effect. The default is yes.


     VerifyReverseMapping

	 Specifies whether sshd	should try to verify  the  remote
	 host  name and	check that the resolved	host name for the
	 remote	IP address maps	back to	the very same IP address.
	 (A  yes  setting means	"verify".) Setting this	parameter
	 to no can be useful where DNS servers might be	down  and
	 thus cause sshd to spend much time trying to resolve the
	 client's IP address to	a name.	This  feature  is  useful
	 for Internet-facing servers. The default is no.


     X11DisplayOffset

	 Specifies the first display number available for  sshd's
	 X11 forwarding. This prevents sshd from interfering with
	 real X11 servers. The default is 10.





SunOS 5.11	    Last change: 26 Mar	2009		       12






File Formats					   sshd_config(4)



     X11Forwarding

	 Specifies  whether  X11  forwarding  is  permitted.  The
	 default  is  yes.  Disabling  X11  forwarding	does  not
	 improve security in any way, as users can always install
	 their own forwarders.

	 When X11 forwarding is	enabled, there can be  additional
	 exposure  to  the  server  and	to client displays if the
	 sshd proxy display is configured to listen on the  wild-
	 card address (see X11UseLocalhost). However, this is not
	 the default. Additionally, the	 authentication	 spoofing
	 and  authentication  data  verification and substitution
	 occur on the client side. The security	risk of	using X11
	 forwarding  is	 that the client's X11 display server can
	 be exposed to attack when the ssh client  requests  for-
	 warding    (see   the	 warnings   for	  ForwardX11   in
	 ssh_config(4)). A system administrator	who wants to pro-
	 tect  clients that expose themselves to attack	by unwit-
	 tingly	requesting X11 forwarding, should  specify  a  no
	 setting.

	 Disabling X11 forwarding does	not  prevent  users  from
	 forwarding  X11  traffic,  as	users  can always install
	 their own forwarders.


     X11UseLocalhost

	 Specifies whether sshd	should bind  the  X11  forwarding
	 server	 to  the  loopback  address  or	 to  the wildcard
	 address. By default, sshd binds the forwarding	server to
	 the  loopback	address	and sets the hostname part of the
	 DISPLAY environment variable to localhost. This prevents
	 remote	 hosts from connecting to the proxy display. How-
	 ever, some older X11 clients  might  not  function  with
	 this  configuration. X11UseLocalhost can be set to no to
	 specify that the forwarding server should  be	bound  to
	 the  wildcard	address.  The argument must be yes or no.
	 The default is	yes.


     XAuthLocation

	 Specifies the location	 of  the  xauth(1)  program.  The
	 default  is /usr/X11/bin/xauth	and sshd attempts to open
	 it when X11 forwarding	is enabled.


  Time Formats
     sshd command-line arguments and configuration  file  options
     that  specify  time can be	expressed using	a sequence of the



SunOS 5.11	    Last change: 26 Mar	2009		       13






File Formats					   sshd_config(4)



     form: time[qualifier,] where  time	 is  a	positive  integer
     value and qualifier is one	of the following:

     <none>    seconds


     s | S     seconds


     m | M     minutes


     h | H     hours


     d | D     days


     w |       weeks



     Each element of the sequence is added together to	calculate
     the total time value. For example:

     600      600 seconds (10 minutes)


     10m      10 minutes


     1h30m    1	hour, 30 minutes (90 minutes)


FILES
     /etc/ssh/sshd_config    Contains  configuration   data   for
			     sshd.  This  file should be writable
			     by	root only, but it is  recommended
			     (though  not  necessary)  that it be
			     world-readable.


ATTRIBUTES
     See attributes(5) for descriptions	of the	following  attri-
     butes:










SunOS 5.11	    Last change: 26 Mar	2009		       14






File Formats					   sshd_config(4)



     ____________________________________________________________
    |	    ATTRIBUTE TYPE	  |	  ATTRIBUTE VALUE	|
    |_____________________________|_____________________________|
    | Availability		  | SUNWsshu			|
    |_____________________________|_____________________________|
    | Interface	Stability	  | Uncommitted			|
    |_____________________________|_____________________________|


SEE ALSO
     login(1), sshd(1M), chroot(2), ssh_config(4), attributes(5),
     kerberos(5)

AUTHORS
     OpenSSH is	a derivative of	the original and free ssh  1.2.12
     release  by  Tatu	Ylonen.	 Aaron Campbell, Bob Beck, Markus
     Friedl, Niels Provos, Theo	de Raadt, and  Dug  Song  removed
     many  bugs,  re-added  recent features, and created OpenSSH.
     Markus Friedl contributed the support for SSH protocol  ver-
     sions  1.5	 and  2.0. Niels Provos	and Markus Friedl contri-
     buted support for privilege separation.


































SunOS 5.11	    Last change: 26 Mar	2009		       15




--Boundary_(ID_1z6XaX/XS+7hxiEVL3Q3Cg)--

