<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH customizing in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746971#M29522</link>
    <description>SSHD2_CONFIG is the server config file.&lt;BR /&gt;SSH2_CONFIG is the client config file.&lt;BR /&gt;Users can have their own client config file.&lt;BR /&gt;&lt;BR /&gt;See&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/732final/aa-rvbua-te/00/00/43-con.html" target="_blank"&gt;http://h71000.www7.hp.com/doc/732final/aa-rvbua-te/00/00/43-con.html&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Wed, 08 Mar 2006 10:50:25 GMT</pubDate>
    <dc:creator>Ian Miller.</dc:creator>
    <dc:date>2006-03-08T10:50:25Z</dc:date>
    <item>
      <title>SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746970#M29521</link>
      <description>Page 28 of &lt;A href="http://h71000.www7.hp.com/openvms/products/ssh/ssh.pdf" target="_blank"&gt;http://h71000.www7.hp.com/openvms/products/ssh/ssh.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;During configuration, the SSHD2_CONFIG. file is copied to TCPIP$SSH_DEVICE:[TCPIP$SSH.SSH2]. When the connection attempt is made from a remote client, the SSH server reads the file and creates the run-time version of the configuration parameters. If you want a different set of parameters, you must create your own version of the configuration file in your SSH subdirectory.&lt;BR /&gt;&lt;BR /&gt;Is it true that the user can decide to have his own server config ? Also on Unix ?&lt;BR /&gt;Can't test it over here.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 08 Mar 2006 10:43:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746970#M29521</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-08T10:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746971#M29522</link>
      <description>SSHD2_CONFIG is the server config file.&lt;BR /&gt;SSH2_CONFIG is the client config file.&lt;BR /&gt;Users can have their own client config file.&lt;BR /&gt;&lt;BR /&gt;See&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/732final/aa-rvbua-te/00/00/43-con.html" target="_blank"&gt;http://h71000.www7.hp.com/doc/732final/aa-rvbua-te/00/00/43-con.html&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Mar 2006 10:50:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746971#M29522</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-03-08T10:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746972#M29523</link>
      <description>IAn,&lt;BR /&gt;&lt;BR /&gt;They are talking here about the SERVER customizing. I tested it on my unborn 7.3 version without success.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Wed, 08 Mar 2006 10:57:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746972#M29523</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-08T10:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746973#M29524</link>
      <description>Does the user run the server?  Does it make&lt;BR /&gt;sense to talk about a user customizing the&lt;BR /&gt;server?&lt;BR /&gt;&lt;BR /&gt;I read the "you" and "your" in your quotation&lt;BR /&gt;as refering to the system manager, not to a&lt;BR /&gt;client/user.&lt;BR /&gt;&lt;BR /&gt;But I'm always open to a good argument.&lt;BR /&gt;&lt;BR /&gt;(Good writing is a rare thing.  "You" is a&lt;BR /&gt;bit ambiguous here, I'd say.)</description>
      <pubDate>Wed, 08 Mar 2006 11:16:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746973#M29524</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2006-03-08T11:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746974#M29525</link>
      <description>Steven,&lt;BR /&gt;&lt;BR /&gt;In my opinion, the config file can be modified.  You can not "create" your own version.&lt;BR /&gt;&lt;BR /&gt;The user file could however be read for creating the encryption process on behalf of the user.&lt;BR /&gt;&lt;BR /&gt;Any case, I did a test with set watch file and found&lt;BR /&gt;&lt;BR /&gt;1) it works without a config file (simply says failed to read but continues as if everything is allowed but without saying it)&lt;BR /&gt;&lt;BR /&gt;2) it isn't trying to find the config file in the user directory&lt;BR /&gt;&lt;BR /&gt;Of course with the pre version.&lt;BR /&gt;&lt;BR /&gt;Wim&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Mar 2006 11:23:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746974#M29525</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-08T11:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746975#M29526</link>
      <description>&amp;gt; In my opinion, the config file can be&lt;BR /&gt;&amp;gt; modified. You can not "create" your own&lt;BR /&gt;&amp;gt; version.&lt;BR /&gt;&lt;BR /&gt;   Hey.  _I_ didn't write the thing.  But&lt;BR /&gt;why can't I "create" my own config file?  I&lt;BR /&gt;may choose to copy a lot of stuff into it&lt;BR /&gt;from the old one.  And even if I simply edit&lt;BR /&gt;the old one, I'll create my own version of&lt;BR /&gt;it.  ";2", is _my_ version.  (Maybe on a&lt;BR /&gt;_UNIX_ system, I can't create my own version,&lt;BR /&gt;but this is VMS.)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; 2) it isn't trying to find the config file&lt;BR /&gt;&amp;gt; in the user directory&lt;BR /&gt;&lt;BR /&gt;It isn't trying to find the _server_ config&lt;BR /&gt;file in the user's directory.  This does not&lt;BR /&gt;amaze me.&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Mar 2006 17:10:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746975#M29526</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2006-03-08T17:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746976#M29527</link>
      <description>Wim,&lt;BR /&gt;&lt;BR /&gt;If the StrictHostKeyChecking variable is set to "yes" in the system-wide ssh2_config. file, then all users will be forced to use only this system-wide ssh2_config file only. In this case any user specific config file from [username.ssh2] directory won't be read.&lt;BR /&gt;&lt;BR /&gt;I did not check this, but you can check by setting this StrictHostKeyChecking variable to 'no" to make sure the user created config file is read.&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Wed, 08 Mar 2006 18:58:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746976#M29527</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-08T18:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746977#M29528</link>
      <description>Wim,&lt;BR /&gt;&lt;BR /&gt;We can create our own config file from TCPIP$TEMPLATES.TLB library and can be modified as per our requirements. These are the commands...&lt;BR /&gt;&lt;BR /&gt;$library/extract=ssh2_config sys$library:tcpip$templates.tlb/out=tcpip$ssh_device:[tcpip$ssh.ssh2]ssh2_config.&lt;BR /&gt;&lt;BR /&gt;$library/extract=sshd2_config sys$library:tcpip$templates.tlb/out=tcpip$ssh_device:[tcpip$ssh.ssh2]sshd2_config.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Wed, 08 Mar 2006 19:08:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746977#M29528</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-08T19:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746978#M29529</link>
      <description>Archunan,&lt;BR /&gt;&lt;BR /&gt;Where did you find that info ?&lt;BR /&gt;&lt;BR /&gt;Normally the parameter is used for copying keys yes/no.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 09 Mar 2006 02:01:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746978#M29529</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-09T02:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746979#M29530</link>
      <description>I checked a source on the internet. The SSH server opens the default server config file or one passed to it as a parameter on the command line.&lt;BR /&gt;&lt;BR /&gt;This is only possible when modifying the startup script (of HP) or by defining a system logical tcpip$ssh_server_params.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 09 Mar 2006 07:04:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746979#M29530</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-09T07:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746980#M29531</link>
      <description>Wim,&lt;BR /&gt;&lt;BR /&gt;Have you had a time to test by setting stricthostkeychecking to "yes" in your server ssh2_config. file.&lt;BR /&gt;&lt;BR /&gt;Sysadmin can use this variable stricthostkeychecking to restrict any user from having their own ssh2_cinfig file.&lt;BR /&gt;&lt;BR /&gt;This variable will be having "no" by default in HP's TCPIP, but Multinet and other's TCPIP product will have stricthostkeychecking variable set to "yes" by default.&lt;BR /&gt;&lt;BR /&gt;So I would suggest you to try changing this variable to "yes", then have your own ssh2_config file in your login dir. Now definetly your own ssh2_config file will be used.&lt;BR /&gt;&lt;BR /&gt;You can copy ssh2_config or you can extract it from sys$library:tcpip$templates.tlb lib.&lt;BR /&gt;&lt;BR /&gt;I tested the extracted ssh2_config file and the system wide TCPIP$SSH_DEVICE:[TCPIP$SSH.SSH2]ssh2_config. file contents will be exactly same.&lt;BR /&gt;&lt;BR /&gt;You can try this if you have tcpip V5.4.&lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Thu, 09 Mar 2006 12:07:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746980#M29531</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-09T12:07:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746981#M29532</link>
      <description>Wim,&lt;BR /&gt;&lt;BR /&gt;On my trial configuring SSH, I just tried changing this variable StrictHostKeyChecking on my own as I saw difft value set for this variable in MULTINET version of ssh2_config file.&lt;BR /&gt;&lt;BR /&gt;Just you can try this.&lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Thu, 09 Mar 2006 12:24:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746981#M29532</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-09T12:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746982#M29533</link>
      <description>Wim,&lt;BR /&gt;I found this for you....&lt;BR /&gt;&lt;A href="http://mvb.saic.com/disk$axpdocmar05/network/tcpip55/RELNOTES/tcp_rnpro_003.html" target="_blank"&gt;http://mvb.saic.com/disk$axpdocmar05/network/tcpip55/RELNOTES/tcp_rnpro_003.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;under "3.11.6 SSH Keys" section, it says.... "A system manager can tighten security by setting the StrictHostKeyChecking variable to "yes" in the systemwide SSH2_CONFIG. file, and forcing users to use only the systemwide version of the file"&lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Thu, 09 Mar 2006 12:32:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746982#M29533</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-09T12:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746983#M29534</link>
      <description>A.,&lt;BR /&gt;&lt;BR /&gt;A D is missing in the config file name. They are talking about the client config, not the server.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 09 Mar 2006 13:15:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746983#M29534</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-09T13:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746984#M29535</link>
      <description>Wim,&lt;BR /&gt;&lt;BR /&gt;I guess the doc talks about both client and sever config file....&lt;BR /&gt;"A system manager can tighten security by setting the StrictHostKeyChecking variable to "yes" in the systemwide SSH2_CONFIG. file, and forcing users to use only the systemwide version of the file" --- here ssh2_config file name is sever config file. Isn't it?.&lt;BR /&gt;&lt;BR /&gt;Please have a trial, it should work.&lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Thu, 09 Mar 2006 13:55:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746984#M29535</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-09T13:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746985#M29536</link>
      <description>Archunan RE "StrictHostKeyChecking Yes" - disallows users from changing the configuration of the ssh client not server.</description>
      <pubDate>Thu, 09 Mar 2006 17:14:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746985#M29536</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-03-09T17:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746986#M29537</link>
      <description>Archunan,&lt;BR /&gt;&lt;BR /&gt;1) The user config file isn't read. Putting the value of strict... to yes will tighten it but it isn't read so tightening is not possible.&lt;BR /&gt;2) The strict... is a client parameter, not a server.&lt;BR /&gt;3) The source are not containing any code for it&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 16 Mar 2006 02:10:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746986#M29537</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-16T02:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746987#M29538</link>
      <description>Ian,&lt;BR /&gt;&lt;BR /&gt;The stricthostkeychecking only indicates how public keys should be copied. It seems that 5.5 has special coding to use the system wide value of the parameter (not my baby on 5.3).&lt;BR /&gt;&lt;BR /&gt;I think the only safe solution is to give the user his own copy of the config file and to disable modifications of it via protections. This way he can not change the values himself.&lt;BR /&gt;&lt;BR /&gt;Wim</description>
      <pubDate>Thu, 16 Mar 2006 02:18:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746987#M29538</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-03-16T02:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSH customizing</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746988#M29539</link>
      <description>Wim/Ian,&lt;BR /&gt;&lt;BR /&gt;Yes I agree, SSH2 and StrictH... is a client side. I wrongly typed SSH2 is severside config file, even after Ian infomed that SSh2 is client and SSHD2 is server.&lt;BR /&gt;&lt;BR /&gt;But by setting Strict...to â  yesâ   in ssh2_config and force the users to use only this file, the private key file: HOSTKEY&lt;BR /&gt;and HOSTKEY.PUB can be created.&lt;BR /&gt;&lt;BR /&gt;if the SSH client and server detect systemwide configuration files from an older version of SSH, the client and server will fail to start.&lt;BR /&gt;&lt;BR /&gt;Also if the SSH client detects a user-creaed config file from an older version of SSH, the client will display the warning and will allow the user to proceed.&lt;BR /&gt;&lt;BR /&gt;Incase if we want to preserve SSH2 or SSHD config files changes.....&lt;BR /&gt;&lt;BR /&gt;we can create our own SSH2 and SSHD config file using the template provided by the new SSH from SYS$LIBRARY:TCPIP$TEMPLATES.TLB in TCPIP$SSH_DEVICE:[TCPIP$SSH.SSH2] dire.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Archunan</description>
      <pubDate>Thu, 16 Mar 2006 16:54:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-customizing/m-p/3746988#M29539</guid>
      <dc:creator>Arch_Muthiah</dc:creator>
      <dc:date>2006-03-16T16:54:14Z</dc:date>
    </item>
  </channel>
</rss>

