Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com Message-ID: <415AB888.2000001@swipnet.se> Date: Wed, 29 Sep 2004 15:28:41 +0200 From: a12 User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax) MIME-Version: 1.0 To: cygwin AT cygwin DOT com Subject: Re: ssh-host-config requires cygminires.dll References: <415975F6 DOT 5030403 AT swipnet DOT se> <415983C7 DOT 9010101 AT swipnet DOT se> <415A73B6 DOT 2030306 AT swipnet DOT se> <415A7C82 DOT 99C307BE AT dessent DOT net> <415A8259 DOT 909 AT swipnet DOT se> <415A98AC DOT B1140D40 AT dessent DOT net> In-Reply-To: <415A98AC.B1140D40@dessent.net> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit X-imss-version: 2.7 X-imss-result: Passed X-imss-scores: Clean:37.42327 C:8 M:0 S:5 R:5 X-imss-settings: Baseline:2 C:1 M:2 S:1 R:1 (0.1500 0.1500) X-IsSubscribed: yes Thank you very much for your reply. Brian Dessent wrote: >a12 wrote: > > > >>/usr/share/doc/Cygwin/openssh.README states: >>If you start sshd as deamon via cygrunsrv.exe you MUST give the >>"-D" option to sshd. Otherwise the service can't get started at all. >> >> > >That isn't telling to you use -D on the cygrunsrv command line >directly. It means that the sshd arguments should contain that >parameter. I.e. you must include -D in the setting of the -a parameter, >such as "cygrunsrv -I sshd -d "CYGWIN sshd" -p /usr/sbin/sshd -a -D" -D >is not a cygrunsrv option, it is the predicate of the -a option. > > > >>ssh_host_*_key.pub are owned by the user that has run ssh-host-config >>Is it OK ? >> >> > >If you ran the above commands they should be owned by SYSTEM. The idea >here is that those files contain the private half of the host's >public/private keypair, and this is sensitive data. So the file should >be readable only by the account that runs the ssh daemon. If you are >the only local user then it doesn't really matter much as you can be >trusted, but on an actual multiuser posix system you would want to >restrict the host key files accordingly. > >Brian > >-- >Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple >Problem reports: http://cygwin.com/problems.html >Documentation: http://cygwin.com/docs.html >FAQ: http://cygwin.com/faq/ > > > > -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/