upstream: make CheckHostIP default to 'no'. It doesn't provide any

perceptible value and makes it much harder for hosts to change host keys,
particularly ones that use IP-based load-balancing.

ok dtucker@

OpenBSD-Commit-ID: 0db98413e82074f78c7d46784b1286d08aee78f0
This commit is contained in:
djm@openbsd.org 2021-01-08 04:49:13 +00:00 committed by Damien Miller
parent 309b642e14
commit 6cb52d5bf7
2 changed files with 6 additions and 6 deletions

View File

@ -1,4 +1,4 @@
/* $OpenBSD: readconf.c,v 1.347 2020/12/22 03:05:31 tb Exp $ */ /* $OpenBSD: readconf.c,v 1.348 2021/01/08 04:49:13 djm Exp $ */
/* /*
* Author: Tatu Ylonen <ylo@cs.hut.fi> * Author: Tatu Ylonen <ylo@cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@ -2297,7 +2297,7 @@ fill_default_options(Options * options)
if (options->batch_mode == -1) if (options->batch_mode == -1)
options->batch_mode = 0; options->batch_mode = 0;
if (options->check_host_ip == -1) if (options->check_host_ip == -1)
options->check_host_ip = 1; options->check_host_ip = 0;
if (options->strict_host_key_checking == -1) if (options->strict_host_key_checking == -1)
options->strict_host_key_checking = SSH_STRICT_HOSTKEY_ASK; options->strict_host_key_checking = SSH_STRICT_HOSTKEY_ASK;
if (options->compression == -1) if (options->compression == -1)

View File

@ -33,8 +33,8 @@
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\" .\"
.\" $OpenBSD: ssh_config.5,v 1.340 2020/12/22 07:40:26 jmc Exp $ .\" $OpenBSD: ssh_config.5,v 1.341 2021/01/08 04:49:13 djm Exp $
.Dd $Mdocdate: December 22 2020 $ .Dd $Mdocdate: January 8 2021 $
.Dt SSH_CONFIG 5 .Dt SSH_CONFIG 5
.Os .Os
.Sh NAME .Sh NAME
@ -421,7 +421,6 @@ or
.It Cm CheckHostIP .It Cm CheckHostIP
If set to If set to
.Cm yes .Cm yes
(the default),
.Xr ssh 1 .Xr ssh 1
will additionally check the host IP address in the will additionally check the host IP address in the
.Pa known_hosts .Pa known_hosts
@ -432,7 +431,8 @@ and will add addresses of destination hosts to
in the process, regardless of the setting of in the process, regardless of the setting of
.Cm StrictHostKeyChecking . .Cm StrictHostKeyChecking .
If the option is set to If the option is set to
.Cm no , .Cm no
(the default),
the check will not be executed. the check will not be executed.
.It Cm Ciphers .It Cm Ciphers
Specifies the ciphers allowed and their order of preference. Specifies the ciphers allowed and their order of preference.