- djm@cvs.openbsd.org 2013/04/19 01:00:10

[sshd_config.5]
     document the requirment that the AuthorizedKeysCommand be owned by root;
     ok dtucker@ markus@
This commit is contained in:
Damien Miller 2013-04-23 15:23:07 +10:00
parent 9303e6527b
commit 467b00c38b
2 changed files with 9 additions and 3 deletions

View File

@ -56,6 +56,11 @@
- djm@cvs.openbsd.org 2013/04/18 02:16:07 - djm@cvs.openbsd.org 2013/04/18 02:16:07
[sftp.c] [sftp.c]
make "sftp -q" do what it says on the sticker: hush everything but errors; make "sftp -q" do what it says on the sticker: hush everything but errors;
ok dtucker@
- djm@cvs.openbsd.org 2013/04/19 01:00:10
[sshd_config.5]
document the requirment that the AuthorizedKeysCommand be owned by root;
ok dtucker@ markus@
20130418 20130418
- (djm) [config.guess config.sub] Update to last versions before they switch - (djm) [config.guess config.sub] Update to last versions before they switch

View File

@ -33,8 +33,8 @@
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\" .\"
.\" $OpenBSD: sshd_config.5,v 1.157 2013/03/07 19:27:25 markus Exp $ .\" $OpenBSD: sshd_config.5,v 1.158 2013/04/19 01:00:10 djm Exp $
.Dd $Mdocdate: March 7 2013 $ .Dd $Mdocdate: April 19 2013 $
.Dt SSHD_CONFIG 5 .Dt SSHD_CONFIG 5
.Os .Os
.Sh NAME .Sh NAME
@ -202,7 +202,8 @@ The default is not to require multiple authentication; successful completion
of a single authentication method is sufficient. of a single authentication method is sufficient.
.It Cm AuthorizedKeysCommand .It Cm AuthorizedKeysCommand
Specifies a program to be used to look up the user's public keys. Specifies a program to be used to look up the user's public keys.
The program will be invoked with a single argument of the username The program must be owned by root and not writable by group or others.
It will be invoked with a single argument of the username
being authenticated, and should produce on standard output zero or being authenticated, and should produce on standard output zero or
more lines of authorized_keys output (see more lines of authorized_keys output (see
.Sx AUTHORIZED_KEYS .Sx AUTHORIZED_KEYS