sshd Keywords

SSH1 SSH2 OpenSSH Keyword Value Meaning
Check Check Check # Any text Comment line
Check
AccountExpireWarningDays
# days Warn user of expiration
Check
AFSTokenPassing
Yes/no Forward AFS tokens to server
N
AllowAgentForwarding
Yes/no Enable agent forwarding
Check
AllowedAuthentications
Auth types Permitted authentication techniques
N
AllowCshrcSourcingWithSubsystems
Yes/no Source shell startup file
F
AllowForwardingPort
Port list Permit forwarding for ports
F
AllowForwardingTo
Host/port list Permit forwarding for hosts
Check N Check
AllowGroups
Group list Access control by Unix group
Check Check
AllowHosts
Host list Access control by hostname
Check Check
AllowSHosts
Host list Access control via .shosts
Check N Check
AllowTcpForwarding
Yes/no Enable TCP port forwarding
N
AllowTcpForwardingFor-Users
User list Per user forwarding
N
AllowTcpForwardingForGroups
Group list Per group forwarding
Check N Check
AllowUsers
User list Access control by username
N
AllowX11Forwarding
Yes/no Enable X forwarding
Check
AuthorizationFile
Filename Location of authorization file
Check Check Check
CheckMail
Yes/no Check new mail on login
N
ChRootGroups
Group list Run chroot() on login
N
ChRootUsers
User list Run chroot() on login
Check 2
Ciphers
Cipher list Select encryption ciphers
F
DenyForwardingPort
Port list Forbid forwarding for ports
F
DenyForwardingTo
Host/port list Forbid forwarding for hosts
Check N Check
DenyGroups
Group list Access control by Unix group
Check Check
DenyHosts
Host list Access control by hostname
Check Check
DenySHosts
Host list Access control via shosts
N
DenyTcpForwardingFor-Users
User list Per user forwarding
N
DenyTcpForwardingForGroups
Group list Per group forwarding
Check N Check
DenyUsers
User list Access control by username
2
DSAAuthentication
Yes/no Permit SSH-2 DSA authentication
Check Check
FascistLogging
Yes/no Verbose mode
Check
ForcedEmptyPasswdChange
Yes/no Change password if empty
Check
ForcedPasswdChange
Yes/no Change password on first login
Check
ForwardAgent
Yes/no Enable agent forwarding
Check
ForwardX11
Yes/no Enable X forwarding
Check
GatewayPorts
Yes/no Gateway all locally forwarded ports
2
HostDSAKey
Filename Location of DSA key file
Check Check
HostKey
Filename Location of host key file
Check
Hostkeyfile
Filename Location of host key file
Check
IdleTimeout
Time Set idle timeout
Check Check Check
IgnoreRhosts
Yes/no Ignore .rhosts files
Check Check
IgnoreRootRhosts
Yes/no Ignore /.rhosts file
Check Check
IgnoreUserKnownHosts
Yes/no Ignore user's known-hosts keys
Check Check Check
KeepAlive
Yes/no Send keepalive packets
Check Check
KerberosAuthentication
Yes/no Permit Kerberos authentication
Check Check
KerberosOrLocalPasswd
Yes/no Kerberos fallback authentication
Check Check
KerberosTgtPassing
Yes/no Support ticket-granting-tickets
Check
KerberosTicketCleanup
Yes/no Destroy ticket cache on logout
Check Check
KeyRegenerationInterval
Time Key regeneration interval
Check Check Check
ListenAddress
IP address Listen on given interface
Check Check Check
LoginGraceTime
Time Time limit for authentication
Check
LogLevel
Syslog level Set syslog level
N
Macs
Algorithm Select MAC algorithm
N
MaxBroadcastsPerSecond
# broadcasts Listen for UDP broadcasts
Check
MaxConnections
# connections Maximum # of simultaneous connections
Check
NoDelay
Yes/no Enable Nagle algorithm
Check Check Check
PasswordAuthentication
Yes/no Permit password authentication
Check
PasswordGuesses
# guesses Limit # of password tries
Check
PasswordExpireWarningDays
# days Warn user before expiration
Check Check Check
PermitEmptyPasswords
Yes/no Permit empty passwords
Check Check Check
PermitRootLogin
Yes/no/ nopwd Permit superuser logins
N
PGPPublicKeyFile
Filename Default location of PGP public key file for authentication
Check Check
PidFile
Filename Location of pid file
Check Check Check
Port
Port number Select server port number
Check Check Check
PrintMotd
Yes/no Print message of the day
Check
Protocol
1/2/1,2 Permit SSH-1 SSH-2 connections
Check
PubKeyAuthentication
Yes/no Permit public-key authentication
Check
PublicHostKeyFile
Filename Location of public host key
Check Check
QuietMode
Yes/no Quiet mode
Check
RandomSeed
Filename Location of random seed file
Check
RandomSeedFile
Filename Location of random seed file
N
RekeyIntervalSeconds
Seconds Frequency of rekeying
Check
RequireReverseMapping
Yes/no Do reverse DNS lookup
Check
RequiredAuthentications
Auth types Required authentication techniques
Check Check Check
RhostsAuthentication
Yes/no Permit .rhosts authentication
Check
RhostsPubKey- Authentication
Yes/no Permit combined authentication
Check Check Check
RhostsRSAAuthentication
Yes/no Permit combined authentication
Check Check Check
RSAAuthentication
Yes/no Permit public-key authentication
Check Check
ServerKeyBits
# bits # of bits in server key
Check
SkeyAuthentication
Yes/no Permit S/Key authentication
Check
Ssh1Compatibility
Yes/no Enable SSH1 compatibility
Check
Sshd1Path
Filename Path to sshd1
Check
SilentDeny
Yes/no DenyHosts prints no message
Check Check Check
StrictModes
Yes/no Strict file/directory permissions
Check Check Check
SyslogFacility
Syslog level Set syslog level
Check
TISAuthentication
Yes/no Permit TIS authentication
Check
Umask
Unix umask Set login umask
Check Check
UseLogin
Yes/no Select login program
Check
UserConfigDirectory
Directory name Location of user SSH2 directories
Check
UserKnownHosts
Yes/no Respect ~/.ssh2/knownhosts
Check
VerboseMode
Yes/no Verbose mode
Check N Check
X11Forwarding
Yes/no Enable X forwarding
Check Check
X11DisplayOffset
# offset Limit X displays for SSH
Check Check
XAuthLocation
Filename Location of xauth