diff options
author | deraadt@openbsd.org <deraadt@openbsd.org> | 2015-08-06 14:53:21 +0000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2015-08-11 18:57:29 +1000 |
commit | 1dc8d93ce69d6565747eb44446ed117187621b26 (patch) | |
tree | 68e850b1c037c7d744836000527320d11b143168 /sshd_config.5 | |
parent | 90a95a4745a531b62b81ce3b025e892bdc434de5 (diff) | |
download | openssh-git-1dc8d93ce69d6565747eb44446ed117187621b26.tar.gz |
add prohibit-password as a synonymn for without-password,
since the without-password is causing too many questions. Harden it to ban
all but pubkey, hostbased, and GSSAPI auth (when the latter is enabled) from
djm, ok markus
Upstream-ID: d53317d7b28942153e6236d3fd6e12ceb482db7a
Diffstat (limited to 'sshd_config.5')
-rw-r--r-- | sshd_config.5 | 11 |
1 files changed, 7 insertions, 4 deletions
diff --git a/sshd_config.5 b/sshd_config.5 index 6eec1f66..58e277f9 100644 --- a/sshd_config.5 +++ b/sshd_config.5 @@ -33,8 +33,8 @@ .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. .\" -.\" $OpenBSD: sshd_config.5,v 1.209 2015/07/30 19:23:02 deraadt Exp $ -.Dd $Mdocdate: July 30 2015 $ +.\" $OpenBSD: sshd_config.5,v 1.210 2015/08/06 14:53:21 deraadt Exp $ +.Dd $Mdocdate: August 6 2015 $ .Dt SSHD_CONFIG 5 .Os .Sh NAME @@ -1204,16 +1204,19 @@ Specifies whether root can log in using .Xr ssh 1 . The argument must be .Dq yes , +.Dq prohibit-password , .Dq without-password , .Dq forced-commands-only , or .Dq no . The default is -.Dq without-password . +.Dq prohibit-password . .Pp If this option is set to +.Dq prohibit-password +or .Dq without-password , -password authentication is disabled for root. +password and keyboard-interactive authentication are disabled for root. .Pp If this option is set to .Dq forced-commands-only , |