summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorDamien Miller <djm@mindrot.org>2005-03-01 21:17:31 +1100
committerDamien Miller <djm@mindrot.org>2005-03-01 21:17:31 +1100
commit1717fd422f2c5691d745a7daf6908df9a6458904 (patch)
tree6f2b0b68ceea61dc780fed386f08b718097cc201
parent70a908ec89b8bd5feb14abed5957ebb063796e94 (diff)
- djm@cvs.openbsd.org 2005/02/28 00:54:10
[ssh_config.5] bz#849: document timeout on untrusted x11 forwarding sessions. Reported by orion AT cora.nwra.com; ok markus@
-rw-r--r--ChangeLog6
-rw-r--r--ssh_config.57
2 files changed, 11 insertions, 2 deletions
diff --git a/ChangeLog b/ChangeLog
index 67ce8f8d..e4ec748f 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -15,6 +15,10 @@
[sshd.8]
add /etc/motd and $HOME/.hushlogin to FILES;
from michael knudsen;
+ - djm@cvs.openbsd.org 2005/02/28 00:54:10
+ [ssh_config.5]
+ bz#849: document timeout on untrusted x11 forwarding sessions. Reported by
+ orion AT cora.nwra.com; ok markus@
20050226
- (dtucker) [openbsd-compat/bsd-openpty.c openbsd-compat/inet_ntop.c]
@@ -2191,4 +2195,4 @@
- (djm) Trim deprecated options from INSTALL. Mention UsePAM
- (djm) Fix quote handling in sftp; Patch from admorten AT umich.edu
-$Id: ChangeLog,v 1.3670 2005/03/01 10:17:09 djm Exp $
+$Id: ChangeLog,v 1.3671 2005/03/01 10:17:31 djm Exp $
diff --git a/ssh_config.5 b/ssh_config.5
index 67b6ca72..8f6d851b 100644
--- a/ssh_config.5
+++ b/ssh_config.5
@@ -34,7 +34,7 @@
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.\" $OpenBSD: ssh_config.5,v 1.41 2005/01/28 18:14:09 jmc Exp $
+.\" $OpenBSD: ssh_config.5,v 1.42 2005/02/28 00:54:10 djm Exp $
.Dd September 25, 1999
.Dt SSH_CONFIG 5
.Os
@@ -359,11 +359,16 @@ option is also enabled.
If this option is set to
.Dq yes
then remote X11 clients will have full access to the original X11 display.
+.Pp
If this option is set to
.Dq no
then remote X11 clients will be considered untrusted and prevented
from stealing or tampering with data belonging to trusted X11
clients.
+Furthermore, the
+.Xr xauth 1
+token used for the session will be set to expire after 20 minutes.
+Remote clients will be refused access after this time.
.Pp
The default is
.Dq no .