summaryrefslogtreecommitdiff
path: root/usr.bin/ssh/sshd_config
AgeCommit message (Expand)Author
2018-04-09the UseLogin option was removed, so remove it here too.T.J. Townsend
2018-02-16stop loading DSA keys by default, remove sshd_config stanza and manpageDamien Miller
2017-03-14Mark the sshd_config UsePrivilegeSeparation option as deprecated,Damien Miller
2016-08-15Catch up with the SSH1 code removal and delete all mention ofChristian Weisgerber
2016-07-11obsolete note about fascistloggin is obsolete. ok djm dtuckerTed Unangst
2016-02-17make sandboxed privilege separation the default, not just for newDamien Miller
2015-08-06add prohibit-password as a synonymn for without-password, since theTheo de Raadt
2015-07-30change default: PermitRootLogin without-passwordTheo de Raadt
2015-04-27Make sshd default to PermitRootLogin=no;Damien Miller
2015-02-02increasing encounters with difficult DNS setups in darknets hasTheo de Raadt
2014-01-10the /etc/ssh/ssh_host_ed25519_key is loaded by default tooDamien Miller
2013-10-29shd_config PermitTTY to disallow TTY allocation, mirroring theDamien Miller
2013-09-07Remove commented-out kerberos/gssapi config options from sample config,Stuart Henderson
2013-05-16Add RekeyLimit to sshd with the same syntax as the client allowing rekeyingDarren Tucker
2013-02-06Change default of MaxStartups to 10:30:100 to start doing random earlyDarren Tucker
2012-10-30new sshd_config option AuthorizedKeysCommand to support fetchingDamien Miller
2012-07-10Turn on systrace sandboxing of pre-auth sshd by default for new installsDamien Miller
2012-04-12mention AuthorizedPrincipalsFile=none defaultDamien Miller
2012-04-12VersionAddendum option to allow server operators to append some arbitraryDamien Miller
2011-05-23allow AuthorizedKeysFile to specify multiple files, separated by spaces.Damien Miller
2011-05-06clarify language about overriding defaults. bz#1892, from Petr CernyDarren Tucker
2010-09-06add ssh_host_ecdsa_key to /etc; from Mattieu Baptiste <mattieu.b@gmail.com>Christian Weisgerber
2009-10-08disable protocol 1 by default (after a transition period of about 10 years)Markus Friedl
2008-07-02increase default size of ssh protocol 1 ephemeral key from 768 to 1024Damien Miller
2008-05-08Make the maximum number of sessions run-time controllable viaDamien Miller
2008-05-07push the sshd_config bits in, spotted by ajacoutot@Pierre-Yves Ritschard
2008-02-08add sshd_config ChrootDirectory option to chroot(2) users to a directory andDamien Miller
2007-08-23Support "Banner=none" to disable displaying of the pre-login banner;Damien Miller
2007-03-19Disable the legacy SSH protocol 1 for new installations viaDamien Miller
2006-07-19Add ForceCommand keyword to sshd_config, equivalent to the "command="Darren Tucker
2005-12-06Add support for tun(4) forwarding over OpenSSH, based on an idea andReyk Floeter
2005-07-25add a new compression method that delays compression until the userMarkus Friedl
2005-05-19whitespace nit, from grunk AT pestilenz.orgDamien Miller
2004-12-23bz #898: support AddressFamily in sshd_config. from peak@argo.troja.mff.cuni.czDamien Miller
2004-05-23Add MaxAuthTries sshd config option; ok markus@Darren Tucker
2003-12-29KeepAlive has been obsoleted, use TCPKeepAlive instead; markus@ OKTodd C. Miller
2003-12-23implement KerberosGetAFSToken server option. ok markus@, beck@Jakob Schlyter
2003-09-29GSSAPICleanupCreds -> GSSAPICleanupCredentialsMarkus Friedl
2003-08-28remove kerberos support from ssh1, since it has been replaced with GSSAPI;Markus Friedl
2003-08-22support GSS API user authentication; patches from Simon Wilkinson,Markus Friedl
2003-08-13remove RhostsAuthentication; suggested by djm@ before; ok djm@, deraadt@,Markus Friedl
2003-07-23remove AFS; itojun@Markus Friedl
2003-06-20sync some implemented options; ok markus@Damien Miller
2003-06-02deprecate VerifyReverseMapping since it's dangerous if combinedMarkus Friedl
2002-09-25sync LoginGraceTime with defaultMarkus Friedl
2002-08-21change LoginGraceTime default to 1 minute; ok mouring@ markus@Kevin Steves
2002-07-30add PermitUserEnvironment (off by default!); from dot@dotat.at; ok provos, de...Markus Friedl
2002-06-20add CompressionMarkus Friedl
2002-06-20refer to config file man pageKevin Steves
2002-05-15re-enable privsep and disable setuid for post-3.2.2Markus Friedl