ssh_config revision 1.17 1 1.14 kim # $NetBSD: ssh_config,v 1.17 2025/10/11 15:45:08 christos Exp $
2 1.17 christos # $OpenBSD: ssh_config,v 1.37 2025/05/06 05:40:56 djm Exp $
3 1.1 christos
4 1.1 christos # This is the ssh client system-wide configuration file. See
5 1.1 christos # ssh_config(5) for more information. This file provides defaults for
6 1.1 christos # users, and the values can be changed in per-user configuration files
7 1.1 christos # or on the command line.
8 1.1 christos
9 1.1 christos # Configuration data is parsed as follows:
10 1.1 christos # 1. command line options
11 1.1 christos # 2. user-specific file
12 1.1 christos # 3. system-wide file
13 1.1 christos # Any configuration value is only changed the first time it is set.
14 1.1 christos # Thus, host-specific definitions should be at the beginning of the
15 1.1 christos # configuration file, and defaults at the end.
16 1.1 christos
17 1.1 christos # Site-wide defaults for some commonly used options. For a comprehensive
18 1.1 christos # list of available options, their meanings and defaults, please see the
19 1.1 christos # ssh_config(5) man page.
20 1.1 christos
21 1.13 kim # NetBSD.org DNS provides SSHFP records - use them when possible
22 1.13 kim Host *.netbsd.org *.NetBSD.org
23 1.13 kim VerifyHostKeyDNS ask
24 1.13 kim
25 1.1 christos # Host *
26 1.1 christos # ForwardAgent no
27 1.1 christos # ForwardX11 no
28 1.1 christos # PasswordAuthentication yes
29 1.1 christos # HostbasedAuthentication no
30 1.14 kim # GSSAPIAuthentication no
31 1.14 kim # GSSAPIDelegateCredentials no
32 1.1 christos # BatchMode no
33 1.16 christos # CheckHostIP no
34 1.1 christos # AddressFamily any
35 1.1 christos # ConnectTimeout 0
36 1.1 christos # StrictHostKeyChecking ask
37 1.1 christos # IdentityFile ~/.ssh/id_rsa
38 1.9 christos # IdentityFile ~/.ssh/id_ecdsa
39 1.9 christos # IdentityFile ~/.ssh/id_ed25519
40 1.1 christos # Port 22
41 1.11 christos # Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc
42 1.11 christos # MACs hmac-md5,hmac-sha1,umac-64 (a] openssh.com
43 1.1 christos # EscapeChar ~
44 1.1 christos # Tunnel no
45 1.1 christos # TunnelDevice any:any
46 1.1 christos # PermitLocalCommand no
47 1.1 christos # VisualHostKey no
48 1.4 adam # ProxyCommand ssh -q -W %h:%p gateway.example.com
49 1.6 christos # RekeyLimit 1G 1h
50 1.15 christos # UserKnownHostsFile ~/.ssh/known_hosts.d/%k
51 1.6 christos
52 1.2 christos # If you use xorg from pkgsrc then uncomment the following line.
53 1.2 christos # XAuthLocation /usr/pkg/bin/xauth
54