Import from Clearcase LIV_TRC6500_V2.2.3
[debian6500.git] / install / cluster / master / etc / ssh / sshd_config
CommitLineData
4e802319 1# Package generated configuration file
2# See the sshd_config(5) manpage for details
3
4# What ports, IPs and protocols we listen for
5Port 22
6# Use these options to restrict which interfaces/protocols sshd will bind to
7#ListenAddress ::
8#ListenAddress 0.0.0.0
9Protocol 2
10# HostKeys for protocol version 2
11HostKey /etc/ssh/ssh_host_rsa_key
12HostKey /etc/ssh/ssh_host_dsa_key
13HostKey /etc/ssh/ssh_host_ecdsa_key
14#Privilege Separation is turned on for security
15UsePrivilegeSeparation yes
16
17# Lifetime and size of ephemeral version 1 server key
18KeyRegenerationInterval 3600
19ServerKeyBits 768
20
21# Logging
22SyslogFacility AUTH
23LogLevel INFO
24
25# Authentication:
26LoginGraceTime 120
27PermitRootLogin yes
28StrictModes yes
29
30RSAAuthentication yes
31PubkeyAuthentication yes
32#AuthorizedKeysFile %h/.ssh/authorized_keys
33
34# Don't read the user's ~/.rhosts and ~/.shosts files
35IgnoreRhosts yes
36# For this to work you will also need host keys in /etc/ssh_known_hosts
37RhostsRSAAuthentication no
38# similar for protocol version 2
39HostbasedAuthentication no
40# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
41#IgnoreUserKnownHosts yes
42
43# To enable empty passwords, change to yes (NOT RECOMMENDED)
44PermitEmptyPasswords no
45
46# Change to yes to enable challenge-response passwords (beware issues with
47# some PAM modules and threads)
48ChallengeResponseAuthentication no
49
50# Change to no to disable tunnelled clear text passwords
51#PasswordAuthentication yes
52
53# Kerberos options
54#KerberosAuthentication no
55#KerberosGetAFSToken no
56#KerberosOrLocalPasswd yes
57#KerberosTicketCleanup yes
58
59# GSSAPI options
60#GSSAPIAuthentication no
61#GSSAPICleanupCredentials yes
62
63X11Forwarding no
64X11DisplayOffset 10
65PrintMotd no
66PrintLastLog yes
67TCPKeepAlive yes
68#UseLogin no
69
70#MaxStartups 10:30:60
71#Banner /etc/issue.net
72
73# Allow client to pass locale environment variables
74AcceptEnv LANG LC_*
75
76Subsystem sftp /usr/lib/openssh/sftp-server
77
78# Set this to 'yes' to enable PAM authentication, account processing,
79# and session processing. If this is enabled, PAM authentication will
80# be allowed through the ChallengeResponseAuthentication and
81# PasswordAuthentication. Depending on your PAM configuration,
82# PAM authentication via ChallengeResponseAuthentication may bypass
83# the setting of "PermitRootLogin without-password".
84# If you just want the PAM account and session checks to run without
85# PAM authentication, then enable this but set PasswordAuthentication
86# and ChallengeResponseAuthentication to 'no'.
87UsePAM no