diff options
Diffstat (limited to 'ssh-agent.0')
| -rw-r--r-- | ssh-agent.0 | 99 |
1 files changed, 48 insertions, 51 deletions
diff --git a/ssh-agent.0 b/ssh-agent.0 index 1ef2702f6d4d..c5fe8b15328c 100644 --- a/ssh-agent.0 +++ b/ssh-agent.0 @@ -1,27 +1,18 @@ SSH-AGENT(1) General Commands Manual SSH-AGENT(1) NAME - ssh-agent M-bM-^@M-^S authentication agent + ssh-agent M-bM-^@M-^S OpenSSH authentication agent SYNOPSIS ssh-agent [-c | -s] [-Dd] [-a bind_address] [-E fingerprint_hash] - [-P pkcs11_whitelist] [-t life] [command [arg ...]] + [-P provider_whitelist] [-t life] [command [arg ...]] ssh-agent [-c | -s] -k DESCRIPTION ssh-agent is a program to hold private keys used for public key - authentication (RSA, DSA, ECDSA, Ed25519). ssh-agent is usually started - in the beginning of an X-session or a login session, and all other - windows or programs are started as clients to the ssh-agent program. - Through use of environment variables the agent can be located and - automatically used for authentication when logging in to other machines - using ssh(1). - - The agent initially does not have any private keys. Keys are added using - ssh(1) (see AddKeysToAgent in ssh_config(5) for details) or ssh-add(1). - Multiple identities may be stored in ssh-agent concurrently and ssh(1) - will automatically use them if present. ssh-add(1) is also used to - remove keys from ssh-agent and to query the keys that are held in one. + authentication. Through use of environment variables the agent can be + located and automatically used for authentication when logging in to + other machines using ssh(1). The options are as follows: @@ -46,13 +37,13 @@ DESCRIPTION -k Kill the current agent (given by the SSH_AGENT_PID environment variable). - -P pkcs11_whitelist - Specify a pattern-list of acceptable paths for PKCS#11 shared - libraries that may be added using the -s option to ssh-add(1). - The default is to allow loading PKCS#11 libraries from - M-bM-^@M-^\/usr/lib/*,/usr/local/lib/*M-bM-^@M-^]. PKCS#11 libraries that do not - match the whitelist will be refused. See PATTERNS in - ssh_config(5) for a description of pattern-list syntax. + -P provider_whitelist + Specify a pattern-list of acceptable paths for PKCS#11 and FIDO + authenticator shared libraries that may be used with the -S or -s + options to ssh-add(1). Libraries that do not match the whitelist + will be refused. See PATTERNS in ssh_config(5) for a description + of pattern-list syntax. The default whitelist is + M-bM-^@M-^\/usr/lib/*,/usr/local/lib/*M-bM-^@M-^]. -s Generate Bourne shell commands on stdout. This is the default if SHELL does not look like it's a csh style of shell. @@ -64,41 +55,47 @@ DESCRIPTION for an identity with ssh-add(1) overrides this value. Without this option the default maximum lifetime is forever. - If a command line is given, this is executed as a subprocess of the - agent. When the command dies, so does the agent. + command [arg ...] + If a command (and optional arguments) is given, this is executed + as a subprocess of the agent. The agent exits automatically when + the command given on the command line terminates. - The idea is that the agent is run in the user's local PC, laptop, or - terminal. Authentication data need not be stored on any other machine, - and authentication passphrases never go over the network. However, the - connection to the agent is forwarded over SSH remote logins, and the user - can thus use the privileges given by the identities anywhere in the - network in a secure way. + There are two main ways to get an agent set up. The first is at the + start of an X session, where all other windows or programs are started as + children of the ssh-agent program. The agent starts a command under + which its environment variables are exported, for example ssh-agent xterm + &. When the command terminates, so does the agent. - There are two main ways to get an agent set up: The first is that the - agent starts a new subcommand into which some environment variables are - exported, eg ssh-agent xterm &. The second is that the agent prints the - needed shell commands (either sh(1) or csh(1) syntax can be generated) - which can be evaluated in the calling shell, eg eval `ssh-agent -s` for - Bourne-type shells such as sh(1) or ksh(1) and eval `ssh-agent -c` for - csh(1) and derivatives. + The second method is used for a login session. When ssh-agent is + started, it prints the shell commands required to set its environment + variables, which in turn can be evaluated in the calling shell, for + example eval `ssh-agent -s`. - Later ssh(1) looks at these variables and uses them to establish a - connection to the agent. + In both cases, ssh(1) looks at these environment variables and uses them + to establish a connection to the agent. - The agent will never send a private key over its request channel. - Instead, operations that require a private key will be performed by the - agent, and the result will be returned to the requester. This way, - private keys are not exposed to clients using the agent. + The agent initially does not have any private keys. Keys are added using + ssh-add(1) or by ssh(1) when AddKeysToAgent is set in ssh_config(5). + Multiple identities may be stored in ssh-agent concurrently and ssh(1) + will automatically use them if present. ssh-add(1) is also used to + remove keys from ssh-agent and to query the keys that are held in one. - A UNIX-domain socket is created and the name of this socket is stored in - the SSH_AUTH_SOCK environment variable. The socket is made accessible - only to the current user. This method is easily abused by root or - another instance of the same user. + Connections to ssh-agent may be forwarded from further remote hosts using + the -A option to ssh(1) (but see the caveats documented therein), + avoiding the need for authentication data to be stored on other machines. + Authentication passphrases and private keys never go over the network: + the connection to the agent is forwarded over SSH remote connections and + the result is returned to the requester, allowing the user access to + their identities anywhere in the network in a secure fashion. - The SSH_AGENT_PID environment variable holds the agent's process ID. +ENVIRONMENT + SSH_AGENT_PID When ssh-agent starts, it stores the name of the agent's + process ID (PID) in this variable. - The agent exits automatically when the command given on the command line - terminates. + SSH_AUTH_SOCK When ssh-agent starts, it creates a UNIX-domain socket and + stores its pathname in this variable. It is accessible + only to the current user, but is easily abused by root or + another instance of the same user. FILES $TMPDIR/ssh-XXXXXXXXXX/agent.<ppid> @@ -108,7 +105,7 @@ FILES agent exits. SEE ALSO - ssh(1), ssh-add(1), ssh-keygen(1), sshd(8) + ssh(1), ssh-add(1), ssh-keygen(1), ssh_config(5), sshd(8) AUTHORS OpenSSH is a derivative of the original and free ssh 1.2.12 release by @@ -117,4 +114,4 @@ AUTHORS created OpenSSH. Markus Friedl contributed the support for SSH protocol versions 1.5 and 2.0. -OpenBSD 6.6 November 30, 2016 OpenBSD 6.6 +OpenBSD 6.6 December 21, 2019 OpenBSD 6.6 |
