summaryrefslogtreecommitdiff
path: root/ssh-agent.0
diff options
context:
space:
mode:
Diffstat (limited to 'ssh-agent.0')
-rw-r--r--ssh-agent.099
1 files changed, 48 insertions, 51 deletions
diff --git a/ssh-agent.0 b/ssh-agent.0
index 1ef2702f6d4d..c5fe8b15328c 100644
--- a/ssh-agent.0
+++ b/ssh-agent.0
@@ -1,27 +1,18 @@
SSH-AGENT(1) General Commands Manual SSH-AGENT(1)
NAME
- ssh-agent M-bM-^@M-^S authentication agent
+ ssh-agent M-bM-^@M-^S OpenSSH authentication agent
SYNOPSIS
ssh-agent [-c | -s] [-Dd] [-a bind_address] [-E fingerprint_hash]
- [-P pkcs11_whitelist] [-t life] [command [arg ...]]
+ [-P provider_whitelist] [-t life] [command [arg ...]]
ssh-agent [-c | -s] -k
DESCRIPTION
ssh-agent is a program to hold private keys used for public key
- authentication (RSA, DSA, ECDSA, Ed25519). ssh-agent is usually started
- in the beginning of an X-session or a login session, and all other
- windows or programs are started as clients to the ssh-agent program.
- Through use of environment variables the agent can be located and
- automatically used for authentication when logging in to other machines
- using ssh(1).
-
- The agent initially does not have any private keys. Keys are added using
- ssh(1) (see AddKeysToAgent in ssh_config(5) for details) or ssh-add(1).
- Multiple identities may be stored in ssh-agent concurrently and ssh(1)
- will automatically use them if present. ssh-add(1) is also used to
- remove keys from ssh-agent and to query the keys that are held in one.
+ authentication. Through use of environment variables the agent can be
+ located and automatically used for authentication when logging in to
+ other machines using ssh(1).
The options are as follows:
@@ -46,13 +37,13 @@ DESCRIPTION
-k Kill the current agent (given by the SSH_AGENT_PID environment
variable).
- -P pkcs11_whitelist
- Specify a pattern-list of acceptable paths for PKCS#11 shared
- libraries that may be added using the -s option to ssh-add(1).
- The default is to allow loading PKCS#11 libraries from
- M-bM-^@M-^\/usr/lib/*,/usr/local/lib/*M-bM-^@M-^]. PKCS#11 libraries that do not
- match the whitelist will be refused. See PATTERNS in
- ssh_config(5) for a description of pattern-list syntax.
+ -P provider_whitelist
+ Specify a pattern-list of acceptable paths for PKCS#11 and FIDO
+ authenticator shared libraries that may be used with the -S or -s
+ options to ssh-add(1). Libraries that do not match the whitelist
+ will be refused. See PATTERNS in ssh_config(5) for a description
+ of pattern-list syntax. The default whitelist is
+ M-bM-^@M-^\/usr/lib/*,/usr/local/lib/*M-bM-^@M-^].
-s Generate Bourne shell commands on stdout. This is the default if
SHELL does not look like it's a csh style of shell.
@@ -64,41 +55,47 @@ DESCRIPTION
for an identity with ssh-add(1) overrides this value. Without
this option the default maximum lifetime is forever.
- If a command line is given, this is executed as a subprocess of the
- agent. When the command dies, so does the agent.
+ command [arg ...]
+ If a command (and optional arguments) is given, this is executed
+ as a subprocess of the agent. The agent exits automatically when
+ the command given on the command line terminates.
- The idea is that the agent is run in the user's local PC, laptop, or
- terminal. Authentication data need not be stored on any other machine,
- and authentication passphrases never go over the network. However, the
- connection to the agent is forwarded over SSH remote logins, and the user
- can thus use the privileges given by the identities anywhere in the
- network in a secure way.
+ There are two main ways to get an agent set up. The first is at the
+ start of an X session, where all other windows or programs are started as
+ children of the ssh-agent program. The agent starts a command under
+ which its environment variables are exported, for example ssh-agent xterm
+ &. When the command terminates, so does the agent.
- There are two main ways to get an agent set up: The first is that the
- agent starts a new subcommand into which some environment variables are
- exported, eg ssh-agent xterm &. The second is that the agent prints the
- needed shell commands (either sh(1) or csh(1) syntax can be generated)
- which can be evaluated in the calling shell, eg eval `ssh-agent -s` for
- Bourne-type shells such as sh(1) or ksh(1) and eval `ssh-agent -c` for
- csh(1) and derivatives.
+ The second method is used for a login session. When ssh-agent is
+ started, it prints the shell commands required to set its environment
+ variables, which in turn can be evaluated in the calling shell, for
+ example eval `ssh-agent -s`.
- Later ssh(1) looks at these variables and uses them to establish a
- connection to the agent.
+ In both cases, ssh(1) looks at these environment variables and uses them
+ to establish a connection to the agent.
- The agent will never send a private key over its request channel.
- Instead, operations that require a private key will be performed by the
- agent, and the result will be returned to the requester. This way,
- private keys are not exposed to clients using the agent.
+ The agent initially does not have any private keys. Keys are added using
+ ssh-add(1) or by ssh(1) when AddKeysToAgent is set in ssh_config(5).
+ Multiple identities may be stored in ssh-agent concurrently and ssh(1)
+ will automatically use them if present. ssh-add(1) is also used to
+ remove keys from ssh-agent and to query the keys that are held in one.
- A UNIX-domain socket is created and the name of this socket is stored in
- the SSH_AUTH_SOCK environment variable. The socket is made accessible
- only to the current user. This method is easily abused by root or
- another instance of the same user.
+ Connections to ssh-agent may be forwarded from further remote hosts using
+ the -A option to ssh(1) (but see the caveats documented therein),
+ avoiding the need for authentication data to be stored on other machines.
+ Authentication passphrases and private keys never go over the network:
+ the connection to the agent is forwarded over SSH remote connections and
+ the result is returned to the requester, allowing the user access to
+ their identities anywhere in the network in a secure fashion.
- The SSH_AGENT_PID environment variable holds the agent's process ID.
+ENVIRONMENT
+ SSH_AGENT_PID When ssh-agent starts, it stores the name of the agent's
+ process ID (PID) in this variable.
- The agent exits automatically when the command given on the command line
- terminates.
+ SSH_AUTH_SOCK When ssh-agent starts, it creates a UNIX-domain socket and
+ stores its pathname in this variable. It is accessible
+ only to the current user, but is easily abused by root or
+ another instance of the same user.
FILES
$TMPDIR/ssh-XXXXXXXXXX/agent.<ppid>
@@ -108,7 +105,7 @@ FILES
agent exits.
SEE ALSO
- ssh(1), ssh-add(1), ssh-keygen(1), sshd(8)
+ ssh(1), ssh-add(1), ssh-keygen(1), ssh_config(5), sshd(8)
AUTHORS
OpenSSH is a derivative of the original and free ssh 1.2.12 release by
@@ -117,4 +114,4 @@ AUTHORS
created OpenSSH. Markus Friedl contributed the support for SSH protocol
versions 1.5 and 2.0.
-OpenBSD 6.6 November 30, 2016 OpenBSD 6.6
+OpenBSD 6.6 December 21, 2019 OpenBSD 6.6