2002-12-23 10:09:59 +08:00
|
|
|
.\" $OpenBSD: ssh-keysign.8,v 1.5 2002/11/24 21:46:24 stevesk Exp $
|
2002-06-07 03:57:33 +08:00
|
|
|
.\"
|
|
|
|
.\" Copyright (c) 2002 Markus Friedl. All rights reserved.
|
|
|
|
.\"
|
|
|
|
.\" Redistribution and use in source and binary forms, with or without
|
|
|
|
.\" modification, are permitted provided that the following conditions
|
|
|
|
.\" are met:
|
|
|
|
.\" 1. Redistributions of source code must retain the above copyright
|
|
|
|
.\" notice, this list of conditions and the following disclaimer.
|
|
|
|
.\" 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
.\" notice, this list of conditions and the following disclaimer in the
|
|
|
|
.\" documentation and/or other materials provided with the distribution.
|
|
|
|
.\"
|
|
|
|
.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
|
|
|
|
.\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
|
|
|
|
.\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
|
|
|
|
.\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
|
|
.\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
|
|
|
.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
.\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
.\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
|
|
|
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
.\"
|
|
|
|
.Dd May 24, 2002
|
|
|
|
.Dt SSH-KEYSIGN 8
|
|
|
|
.Os
|
|
|
|
.Sh NAME
|
|
|
|
.Nm ssh-keysign
|
|
|
|
.Nd ssh helper program for hostbased authentication
|
|
|
|
.Sh SYNOPSIS
|
2002-06-11 23:50:13 +08:00
|
|
|
.Nm
|
2002-06-07 03:57:33 +08:00
|
|
|
.Sh DESCRIPTION
|
|
|
|
.Nm
|
|
|
|
is used by
|
|
|
|
.Xr ssh 1
|
2002-06-11 23:50:13 +08:00
|
|
|
to access the local host keys and generate the digital signature
|
|
|
|
required during hostbased authentication with SSH protocol version 2.
|
2002-07-04 08:19:40 +08:00
|
|
|
.Pp
|
|
|
|
.Nm
|
|
|
|
is disabled by default and can only be enabled in the
|
2002-12-23 10:09:59 +08:00
|
|
|
global client configuration file
|
2002-07-04 08:19:40 +08:00
|
|
|
.Pa /etc/ssh/ssh_config
|
|
|
|
by setting
|
2002-11-09 23:52:31 +08:00
|
|
|
.Cm EnableSSHKeysign
|
2002-07-04 08:19:40 +08:00
|
|
|
to
|
|
|
|
.Dq yes .
|
|
|
|
.Pp
|
2002-06-07 03:57:33 +08:00
|
|
|
.Nm
|
|
|
|
is not intended to be invoked by the user, but from
|
|
|
|
.Xr ssh 1 .
|
|
|
|
See
|
|
|
|
.Xr ssh 1
|
|
|
|
and
|
|
|
|
.Xr sshd 8
|
|
|
|
for more information about hostbased authentication.
|
2002-06-11 23:50:13 +08:00
|
|
|
.Sh FILES
|
|
|
|
.Bl -tag -width Ds
|
2002-07-04 08:19:40 +08:00
|
|
|
.It Pa /etc/ssh/ssh_config
|
|
|
|
Controls whether
|
|
|
|
.Nm
|
|
|
|
is enabled.
|
2002-06-11 23:50:13 +08:00
|
|
|
.It Pa /etc/ssh/ssh_host_dsa_key, /etc/ssh/ssh_host_rsa_key
|
|
|
|
These files contain the private parts of the host keys used to
|
|
|
|
generate the digital signature. They
|
|
|
|
should be owned by root, readable only by root, and not
|
|
|
|
accessible to others.
|
|
|
|
Since they are readable only by root,
|
|
|
|
.Nm
|
|
|
|
must be set-uid root if hostbased authentication is used.
|
|
|
|
.El
|
2002-06-07 03:57:33 +08:00
|
|
|
.Sh SEE ALSO
|
|
|
|
.Xr ssh 1 ,
|
2002-06-11 23:50:13 +08:00
|
|
|
.Xr ssh-keygen 1 ,
|
2002-07-04 08:19:40 +08:00
|
|
|
.Xr ssh_config 5 ,
|
2002-06-07 03:57:33 +08:00
|
|
|
.Xr sshd 8
|
|
|
|
.Sh AUTHORS
|
|
|
|
Markus Friedl <markus@openbsd.org>
|
|
|
|
.Sh HISTORY
|
|
|
|
.Nm
|
|
|
|
first appeared in
|
|
|
|
.Ox 3.2 .
|