| Summary: | Document IdentityFile=none and clarify interaction of defaults with IdentitiesOnly | ||
|---|---|---|---|
| Product: | Portable OpenSSH | Reporter: | osnuc <openssh> |
| Component: | Documentation | Assignee: | Assigned to nobody <unassigned-bugs> |
| Status: | REOPENED --- | ||
| Severity: | normal | CC: | djm |
| Priority: | P5 | ||
| Version: | 8.0p1 | ||
| Hardware: | Other | ||
| OS: | All | ||
|
Description
osnuc
2019-10-09 19:54:51 AEDT
This was fixed last September in commit 7047d5afe3 and should be in OpenSSH 8.2 Hi, thanks for the update on this. As far as I can see, the special "none" string for IdentityFile still remains undocumented. So as a minimum, can you please make the following change: * in the IdentityFile section, mention the special "none" value. Additionally, a common use case for IdentitiesOnly is to set it to yes globally, and then set IdentityFile for each host, with the intention of *only* trying the explicitly configured key. However, this will not have the desired effect, since OpenSSH will still try (falling back on?) keys with standard names. For this reason, it would be helpful to add the following: * in the IdentitiesOnly section, mention also needing to set IdentityFile to none if the user does not want to fall back on SSH keys with standard names. |