Idletimeout patch

Kevin Steves stevesk at pobox.com
Sat Aug 18 03:12:41 EST 2001


On Thu, 16 Aug 2001 mouring at etoh.eviladmin.org wrote:
:This is pretty much equiv to idled or the hundreds of other idle testing
:deamons out there.   Except it's more limited.   Idled is much nicer for
:doing such things.  It gives you more control the whole process so you can
:disable it for certian groups of people.  Your patch does not so to most
:people it would be useless.

actually, idletimeout needs to be internal.  an external program can't
determine whether no data has passed over a channel for the timeout
period.  it also needs to know about things like clientalive messages,
which jani has tried to tackle.  we also want a key file option to be able
to override the server value.

i think this is an important configuration option that can be used to
increase security.




More information about the openssh-unix-dev mailing list