]>
Commit | Line | Data |
---|---|---|
8efc0c15 | 1 | # This is ssh server systemwide configuration file. |
2 | ||
3 | Port 22 | |
4 | ListenAddress 0.0.0.0 | |
d2dcff5f | 5 | HostKey @sysconfdir@/ssh_host_key |
8efc0c15 | 6 | ServerKeyBits 768 |
7 | LoginGraceTime 600 | |
8 | KeyRegenerationInterval 3600 | |
9 | PermitRootLogin yes | |
8efc0c15 | 10 | StrictModes yes |
b4748e2f | 11 | X11Forwarding no |
8efc0c15 | 12 | X11DisplayOffset 10 |
8efc0c15 | 13 | PrintMotd yes |
14 | KeepAlive yes | |
272b7f60 | 15 | CheckMail no |
16 | UseLogin no | |
dd092f97 | 17 | |
18 | # | |
19 | # Loglevel replaces QuietMode and FascistLogging | |
20 | # | |
8efc0c15 | 21 | SyslogFacility AUTH |
dd092f97 | 22 | LogLevel INFO |
272b7f60 | 23 | |
8efc0c15 | 24 | # |
f1bcacf9 | 25 | # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts |
8efc0c15 | 26 | # |
272b7f60 | 27 | RhostsRSAAuthentication no |
28 | ||
b4748e2f | 29 | # |
30 | # Don't read ~/.rhosts and ~/.shosts files | |
31 | # | |
32 | IgnoreRhosts yes | |
dd092f97 | 33 | RhostsAuthentication no |
b4748e2f | 34 | |
35 | # | |
36 | # Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication | |
37 | # | |
38 | #IgnoreUserKnownHosts yes | |
39 | ||
8efc0c15 | 40 | RSAAuthentication yes |
41 | ||
42 | # To disable tunneled clear text passwords, change to no here! | |
43 | PasswordAuthentication yes | |
44 | PermitEmptyPasswords no | |
272b7f60 | 45 | |
46 | # | |
47 | # Uncomment to disable s/key passwords (must be compiled with s/key support) | |
48 | # | |
8efc0c15 | 49 | #SkeyAuthentication no |
50 | ||
272b7f60 | 51 | # |
52 | # To change Kerberos options (must be compiled with Kerberos support) | |
53 | # | |
8efc0c15 | 54 | #KerberosAuthentication no |
55 | #KerberosOrLocalPasswd yes | |
56 | #AFSTokenPassing no | |
57 | #KerberosTicketCleanup no | |
8efc0c15 | 58 | # Kerberos TGT Passing does only work with the AFS kaserver |
59 | #KerberosTgtPassing yes |