[Bug 3361] document that SessionType none prevents e.g. execution of authorized_keys’ command=

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Wed Nov 10 10:04:22 AEDT 2021


https://bugzilla.mindrot.org/show_bug.cgi?id=3361

Damien Miller <djm at mindrot.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |djm at mindrot.org

--- Comment #1 from Damien Miller <djm at mindrot.org> ---
This is the current description in the manpage:

> SessionType
>     May be used to either request invocation of a subsystem on the
>     remote system, or to prevent the execution of a remote command at
>     all.  The latter is useful for just forwarding ports.  The argu‐
>     ment to this keyword must be *none* (same as the -N option),
>     *subsystem* (same as the -s option) or *default* (shell or command
>     execution).

IMO this is pretty clear already - the first sentence mentions the
behaviour of blocking all shell/command execution and the third
describes which does which.

-- 
You are receiving this mail because:
You are watching the assignee of the bug.
You are watching someone on the CC list of the bug.


More information about the openssh-bugs mailing list