summaryrefslogtreecommitdiff
path: root/security/openssh/MESSAGE
blob: e96c0208959e6f2d4f952c970e7431eac43b6539 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
===========================================================================
$NetBSD: MESSAGE,v 1.9 2002/06/29 01:34:59 grant Exp $

                           *===* NOTICE *===*

The config files for ${PKGNAME} must be located in:

	${PKG_SYSCONFDIR}

and the example files are located in ${EGDIR}.
If you have existing config files for OpenSSH located at /etc/ssh.conf
and /etc/sshd.conf, then you will have to copy them:

	/etc/ssh.conf  --> ${PKG_SYSCONFDIR}/ssh_config
	/etc/sshd.conf --> ${PKG_SYSCONFDIR}/sshd_config

You need to create UID sshd, and GID sshd, for privilege separation.  For
security reasons, UsePrivilegeSeparation has to be yes (the default value).
For example, add the following into /etc/passwd and /etc/group:

	sshd:*:16:16::0:0:sshd privsep:/var/chroot/sshd:/sbin/nologin
	sshd:*:16:

===========================================================================