66 lines
2.1 KiB
Groff
66 lines
2.1 KiB
Groff
.TH SSHD 1
|
|
.SH NAME
|
|
sshd \- MontaukOS SSH-2 server
|
|
.SH SYNOPSIS
|
|
.B sshd
|
|
.SH DESCRIPTION
|
|
.B sshd
|
|
accepts SSH-2 connections and gives each authenticated user a MontaukOS shell.
|
|
|
|
It is normally launched automatically by
|
|
.BR init (1)
|
|
and does not require direct user interaction. Remote access is disabled by
|
|
default; enable it from Settings > SSH Server, which sets
|
|
.I services.ssh.enabled
|
|
in
|
|
.IR 0:/config/init.toml .
|
|
The change takes effect on the next boot.
|
|
.SH AUTHENTICATION
|
|
Passwords are the only supported method, checked against the MontaukOS account
|
|
database. A user must additionally be listed in the
|
|
.I [allow]
|
|
table of
|
|
.I 0:/config/ssh.toml
|
|
before a login is accepted; users absent from that table are refused. The
|
|
Settings applet maintains this table.
|
|
|
|
Failed passwords are delayed, and a connection is dropped after eight attempts.
|
|
.SH CONFIGURATION
|
|
.TP
|
|
.I 0:/config/ssh.toml
|
|
Listening port
|
|
.RI ( server.port ,
|
|
default 22) and the per-user
|
|
.I [allow]
|
|
table.
|
|
.TP
|
|
.I 0:/config/ssh_hostkey.toml
|
|
The RSA host key, generated on first start. Note that the filesystem has no
|
|
permission model, so this file is readable by any local process; keeping it
|
|
separate from
|
|
.I ssh.toml
|
|
limits exposure but is not access control.
|
|
.SH DIAGNOSTICS
|
|
Messages go to the boot console only. They do not appear in
|
|
.BR klog (1):
|
|
.B SYS_PRINT
|
|
writes the kernel terminal rather than the kernel log ring, and is discarded
|
|
entirely once the desktop suppresses console output. There is currently nowhere
|
|
to read them from on a running desktop.
|
|
.SH PROTOCOL
|
|
Key exchange is diffie-hellman-group14-sha256 with an rsa-sha2-256 host key;
|
|
the transport uses aes128-ctr with hmac-sha2-256. Client-initiated rekeying is
|
|
supported. Only one session channel per connection is served, and connections
|
|
are handled one at a time.
|
|
.SH LIMITATIONS
|
|
Public key authentication, port forwarding, X11 forwarding, SFTP and SCP are not
|
|
implemented.
|
|
|
|
.I exec
|
|
requests run the command by feeding it to an interactive shell, so the shell
|
|
prompt and the echoed command line appear in the output. Scripts that parse
|
|
remote command output should account for this.
|
|
.SH SEE ALSO
|
|
.BR shell (1),
|
|
.BR init (1)
|