Professional Documents
Culture Documents
OpenSSH V1R2
Richard Theis (rtheis@us.ibm.com)
IBM Rochester, MN
Session 9684
u!ust "", #$""
2011 IBM Corporation
2
Trademars and !is"laimers
See #ttp$//%%%&i'm&"om/le(al/"op)trade&s#tml for a list of IBM trademars&
T#e follo%in( are trademars or re(istered trademars of ot#er "ompanies
%NI& is a re!istered trademar' o( The )*en +rou* in the %nited States and other countries
,-RT. is a re!istered trademar' and ser/ice mar' o( ,arne!ie Me00on %ni/ersit1.
ssh. is a re!istered trademar' o( SS2 ,ommunications Securit1 ,or*
& 3indo4 S1stem is a trademar' o( & ,onsortium, Inc
*ll ot#er prod+"ts ma) 'e trademars or re(istered trademars of t#eir respe"ti,e "ompanies
-otes$
5er(ormance is in Interna0 Throu!h*ut Rate (ITR) ratio based on measurements and *ro6ections usin! standard IBM benchmar's in a contro00ed en/ironment.
The actua0 throu!h*ut that an1 user 4i00 e7*erience 4i00 /ar1 de*endin! u*on considerations such as the amount o( mu0ti*ro!rammin! in the user8s 6ob stream,
the I9) con(i!uration, the stora!e con(i!uration, and the 4or'0oad *rocessed. There(ore, no assurance can be !i/en that an indi/idua0 user 4i00 achie/e
throu!h*ut im*ro/ements e:ui/a0ent to the *er(ormance ratios stated here.
IBM hard4are *roducts are manu(actured (rom ne4 *arts, or ne4 and ser/iceab0e used *arts. Re!ard0ess, our 4arrant1 terms a**01.
00 customer e7am*0es cited or described in this *resentation are *resented as i00ustrations o( the manner in 4hich some customers ha/e used IBM *roducts and
the resu0ts the1 ma1 ha/e achie/ed. ctua0 en/ironmenta0 costs and *er(ormance characteristics 4i00 /ar1 de*endin! on indi/idua0 customer con(i!urations
and conditions.
This *ub0ication 4as *roduced in the %nited States. IBM ma1 not o((er the *roducts, ser/ices or (eatures discussed in this document in other countries, and the
in(ormation ma1 be sub6ect to chan!e 4ithout notice. ,onsu0t 1our 0oca0 IBM business contact (or in(ormation on the *roduct or ser/ices a/ai0ab0e in 1our area.
00 statements re!ardin! IBM8s (uture direction and intent are sub6ect to chan!e or 4ithdra4a0 4ithout notice, and re*resent !oa0s and ob6ecti/es on01.
In(ormation about non;IBM *roducts is obtained (rom the manu(acturers o( those *roducts or their *ub0ished announcements. IBM has not tested those *roducts
and cannot con(irm the *er(ormance, com*atibi0it1, or an1 other c0aims re0ated to non;IBM *roducts. <uestions on the ca*abi0ities o( non;IBM *roducts shou0d
be addressed to the su**0iers o( those *roducts.
5rices sub6ect to chan!e 4ithout notice. ,ontact 1our IBM re*resentati/e or Business 5artner (or the most current *ricin! in 1our !eo!ra*h1.
2011 IBM Corporation
.
*(enda
// O,er,ie% 00
5ac'a!in! and insta00ation
Re:uirements addressed
Ser/ice notes
Mi!ration and coe7istence
Troub0eshootin! in(ormation
**endi7
2011 IBM Corporation
1
O,er,ie%$ OpenSSH
2#at is OpenSSH3
No 0on!er a/ai0ab0e
2011 IBM Corporation
8
O,er,ie%$ OpenSSH for z/OS Prod+"ts
N-3A sshd, sc*, s(t* and s(t*;ser/er must ha/e the 5?;
authori>ed e7tended attribute set (i.e. e7tattr Ja)
Misce00aneous re:uirements
2011 IBM Corporation
14
Re?+irements addressed$ @p(rade
Pro'lem statement
Sol+tion
Benefits
Pro'lem statement
Sol+tion
Benefits
Pro'lem statement
Sol+tion
Benefits
Pro'lem statement
Sol+tion
Benefits
Pro'lem statement
Sol+tion
Benefits
Pro'lem statement
Sol+tion
Benefits
Mi!ration actions
,oe7istence considerations
2#at "#an(ed
I( 1ou use the s(t* command 4ith the Kb o*tion and re:uire
*ass4ord, *ass*hrase or host 'e1 *rom*ts durin!
authentication. ?or e7am*0e, i( 1ou use the SS2OSI5SS
en/ironment /ariab0e (or user authentication, this mi!ration
action is re:uired since usin! SS2OSI5SS re:uires a
*ass*hrase *rom*t.
2011 IBM Corporation
.8
Mi(ration a"tion$ sftp 'at"# mode
:Contin+ed<
Mi(ration a"tion
Referen"es
2#at "#an(ed
Mi(ration a"tion
00 )*enSS2 commands
Referen"es
2#at "#an(ed
Mi(ration a"tion
s(t* command
Referen"es
2#at "#an(ed
Mi(ration a"tion
00 )*enSS2 commands
Referen"es
2#at "#an(ed
Mi(ration a"tion
ssh command
2011 IBM Corporation
14
Mi(ration a"tion$ ss#d f+ll pat# name
2#at "#an(ed
Mi(ration a"tion
,han!e the startu* *rocess to use the (u00 *ath name instead
o( a re0ati/e *ath name.
sshd command
2011 IBM Corporation
15
Mi(ration a"tion$ *ddress parsin(
"#an(es
2#at "#an(ed
Mi(ration a"tion
2#at "#an(ed
Mi(ration a"tion
2#at "#an(ed
Mi(ration a"tion
2#at "#an(ed
Mi(ration a"tion
00 )*enSS2 commands
2011 IBM Corporation
4.
Mi(ration a"tion$ Messa(e n+m'ers
2#at "#an(ed
Mi(ration a"tion
00 )*enSS2 commands
2011 IBM Corporation
44
Mi(ration a"tion$ !efa+lt ,al+e "#an(e
for "ip#ers list
2#at "#an(ed
I( 1ou used the *re/ious de(au0t 0ist and do not 4ant to a00o4
the ne4 ci*hers or the ne4 order o( the *re(erred ci*hers.
Mi(ration a"tion
2#at "#an(ed
I( 1ou used the *re/ious de(au0t 0ist and do not 4ant to a00o4
the ne4 M,.
Mi(ration a"tion
2#at "#an(ed
Mi(ration a"tion
2#at "#an(ed
Mi(ration a"tion
2#at "#an(ed
5re/ious01, i( the (i0e name 4as not s*eci(ied, a *rom*t (or the
(i0e name 4as issued. No4 the de(au0t (i0e names (or RS
and =S 'e1s are used instead.
Mi(ration a"tion
2#at "#an(ed
Mi(ration a"tion
None.
2#at "#an(ed
Mi(ration a"tion
ssh;'e1!en
2011 IBM Corporation
51
Coe>isten"e "onsiderations
Coe>isten"e "onsiderations
ssh and sc* c0ients 4i00 han! i( ser/er (orces s(t* (e.!.
?orce,ommand interna0;s(t*) ; this is 4or'in!;as;desi!ned
See the GDimitin! (i0e s1stem name s*ace (or s(t* usersH
section in the userLs !uide (or more in(ormation on settin! u* a
restricted en/ironment (or SS2 c0ients.
2011 IBM Corporation
80
Tro+'les#ootin( information$ SMB
>9)S "."$ and >9)S "."" on01A @eri(1 the 5T?s (or 5Rs
5I86B#9 and )#94$" are a**0ied
Se"+rit) en#an"ements
Pro(rammin( s+pport
ss#
ss# :"ontin+ed<
ss#H"onfi(
ss#d
ss#dH"onfi(
s"p
sftp
sftpDser,er
ss#De)s"an
ss#De)(en
ss#Dadd
ss#DrandD#elper
:-;2< zosHss#H"onfi(
:-;2< zosH+serHss#H"onfi(
:-;2< zosHss#dH"onfi(
C#an(ed samples
9sam*0es9sshOcon(i!
9sam*0es9sshdOcon(i!
9sam*0es9modu0i
-e% samples
9sam*0es9>osOsshOcon(i!
9sam*0es9>osOuserOsshOcon(i!
9sam*0es9>osOsshdOcon(i!
9sam*0es9sshOsm(.h
?)TSM?EE in STS".M,DIB
2011 IBM Corporation
=.
2#atIs ne% or "#an(ed$ !etails
OS)SOSS2O5RN+O,M=SOTIM-)%T (ssh;rand;he0*er)
OS)SOSS2=O,)N?I+ (sshd)
OS)SOSS2OI-TORIN+ (ssh;add)
OS)SO%S-ROSS2O,)N?I+ (ssh)
2e'site Referen"es
)*enSS2A htt*A99444.o*enssh.or!9
)*enSSDA htt*A99444.o*enss0.or!9
>0ibA htt*A99444.>0ib.net9
2011 IBM Corporation
=5
*ppendi>
I-T?A htt*A99444.iet(.or!9
Sho*>SeriesA
htt*sA99444"4.so(t4are.ibm.com94eba**9Sho*>Series9Sho*>Series.6s*