summaryrefslogtreecommitdiff
path: root/ssh.1
diff options
context:
space:
mode:
authormouring <mouring>2001-01-29 08:37:08 +0000
committermouring <mouring>2001-01-29 08:37:08 +0000
commitc86f23f2e4a5a9e5c70f78a371c0e54d1ae1e1ee (patch)
tree6781521a8c564b41f7e215d538c6021bf8924989 /ssh.1
parent47edf046f76069af71fa806813b34522e9ed9335 (diff)
downloadopenssh-c86f23f2e4a5a9e5c70f78a371c0e54d1ae1e1ee.tar.gz
- stevesk@cvs.openbsd.org 2001/01/28 20:36:16
[readconf.c ssh.1] ``StrictHostKeyChecking ask'' documentation and small cleanup. ok markus@
Diffstat (limited to 'ssh.1')
-rw-r--r--ssh.135
1 files changed, 24 insertions, 11 deletions
diff --git a/ssh.1 b/ssh.1
index 621d1af2..34f94988 100644
--- a/ssh.1
+++ b/ssh.1
@@ -34,7 +34,7 @@
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.\" $OpenBSD: ssh.1,v 1.78 2001/01/28 10:24:04 markus Exp $
+.\" $OpenBSD: ssh.1,v 1.79 2001/01/28 20:36:16 stevesk Exp $
.Dd September 25, 1999
.Dt SSH 1
.Os
@@ -924,28 +924,41 @@ The default is
If this flag is set to
.Dq yes ,
.Nm
-ssh will never automatically add host keys to the
+will never automatically add host keys to the
.Pa $HOME/.ssh/known_hosts
and
.Pa $HOME/.ssh/known_hosts2
-files, and refuses to connect hosts whose host key has changed.
+files, and refuses to connect to hosts whose host key has changed.
This provides maximum protection against trojan horse attacks.
However, it can be somewhat annoying if you don't have good
.Pa /etc/ssh_known_hosts
and
.Pa /etc/ssh_known_hosts2
files installed and frequently
-connect new hosts.
-Basically this option forces the user to manually
-add any new hosts.
-Normally this option is disabled, and new hosts
-will automatically be added to the known host files.
+connect to new hosts.
+This option forces the user to manually
+add all new hosts.
+If this flag is set to
+.Dq no ,
+.Nm
+will automatically add new host keys to the
+user known hosts files.
+If this flag is set to
+.Dq ask ,
+new host keys
+will be added to the user known host files only after the user
+has confirmed that is what they really want to do, and
+.Nm
+will refuse to connect to hosts whose host key has changed.
The host keys of
-known hosts will be verified automatically in either case.
+known hosts will be verified automatically in all cases.
The argument must be
-.Dq yes
+.Dq yes ,
+.Dq no
or
-.Dq no .
+.Dq ask .
+The default is
+.Dq ask .
.It Cm UsePrivilegedPort
Specifies whether to use a privileged port for outgoing connections.
The argument must be