upstream commit

cidr permitted for {allow,deny}users; from lars nooden ok djm

Upstream-ID: 13e7327fe85f6c63f3f7f069e0fdc8c351515d11
This commit is contained in:
jmc@openbsd.org 2016-04-27 13:53:48 +00:00 committed by Damien Miller
parent b6e0140a5a
commit ee1e0a16ff

View File

@ -33,8 +33,8 @@
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\" .\"
.\" $OpenBSD: sshd_config.5,v 1.221 2016/03/17 17:19:43 djm Exp $ .\" $OpenBSD: sshd_config.5,v 1.222 2016/04/27 13:53:48 jmc Exp $
.Dd $Mdocdate: March 17 2016 $ .Dd $Mdocdate: April 27 2016 $
.Dt SSHD_CONFIG 5 .Dt SSHD_CONFIG 5
.Os .Os
.Sh NAME .Sh NAME
@ -173,6 +173,8 @@ By default, login is allowed for all users.
If the pattern takes the form USER@HOST then USER and HOST If the pattern takes the form USER@HOST then USER and HOST
are separately checked, restricting logins to particular are separately checked, restricting logins to particular
users from particular hosts. users from particular hosts.
HOST criteria may additionally contain addresses to match in CIDR
address/masklen format.
The allow/deny directives are processed in the following order: The allow/deny directives are processed in the following order:
.Cm DenyUsers , .Cm DenyUsers ,
.Cm AllowUsers , .Cm AllowUsers ,
@ -560,6 +562,8 @@ By default, login is allowed for all users.
If the pattern takes the form USER@HOST then USER and HOST If the pattern takes the form USER@HOST then USER and HOST
are separately checked, restricting logins to particular are separately checked, restricting logins to particular
users from particular hosts. users from particular hosts.
HOST criteria may additionally contain addresses to match in CIDR
address/masklen format.
The allow/deny directives are processed in the following order: The allow/deny directives are processed in the following order:
.Cm DenyUsers , .Cm DenyUsers ,
.Cm AllowUsers , .Cm AllowUsers ,