summaryrefslogtreecommitdiffstats
path: root/sshd_config.5
diff options
context:
space:
mode:
authorjmc@openbsd.org <jmc@openbsd.org>2016-04-27 15:53:48 +0200
committerDamien Miller <djm@mindrot.org>2016-04-28 11:55:28 +0200
commitee1e0a16ff2ba41a4d203c7670b54644b6c57fa6 (patch)
treef6ec124816df955bcc39c7ec331a5b10f7ceb8c1 /sshd_config.5
parentupstream commit (diff)
downloadopenssh-ee1e0a16ff2ba41a4d203c7670b54644b6c57fa6.tar.xz
openssh-ee1e0a16ff2ba41a4d203c7670b54644b6c57fa6.zip
upstream commit
cidr permitted for {allow,deny}users; from lars nooden ok djm Upstream-ID: 13e7327fe85f6c63f3f7f069e0fdc8c351515d11
Diffstat (limited to '')
-rw-r--r--sshd_config.58
1 files changed, 6 insertions, 2 deletions
diff --git a/sshd_config.5 b/sshd_config.5
index 433b8f2c1..63807c030 100644
--- a/sshd_config.5
+++ b/sshd_config.5
@@ -33,8 +33,8 @@
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.\" $OpenBSD: sshd_config.5,v 1.221 2016/03/17 17:19:43 djm Exp $
-.Dd $Mdocdate: March 17 2016 $
+.\" $OpenBSD: sshd_config.5,v 1.222 2016/04/27 13:53:48 jmc Exp $
+.Dd $Mdocdate: April 27 2016 $
.Dt SSHD_CONFIG 5
.Os
.Sh NAME
@@ -173,6 +173,8 @@ By default, login is allowed for all users.
If the pattern takes the form USER@HOST then USER and HOST
are separately checked, restricting logins to particular
users from particular hosts.
+HOST criteria may additionally contain addresses to match in CIDR
+address/masklen format.
The allow/deny directives are processed in the following order:
.Cm DenyUsers ,
.Cm AllowUsers ,
@@ -560,6 +562,8 @@ By default, login is allowed for all users.
If the pattern takes the form USER@HOST then USER and HOST
are separately checked, restricting logins to particular
users from particular hosts.
+HOST criteria may additionally contain addresses to match in CIDR
+address/masklen format.
The allow/deny directives are processed in the following order:
.Cm DenyUsers ,
.Cm AllowUsers ,