92
•
Configuring and Running SSH2
HP NonStop SSH Reference Manual
•
Some of the privileged commands in SSHCOM are critical to the security of the system. Therefore granting
access to other user accounts than super.super must be carefully considered.
•
The parameters must be set contiguously, i.e. if one parameter FULLSSHCOMACCESSUSER<k> is not
defined the checking of FULLSSHCOMACCESSUSER<i> parameters stops.
•
This parameter set is valid whether a thawed OBJECTTYPE USER record exists in Safeguard or not. But if a
user is configured with C access in the OBJECTTYPE USER record as well as mentioned in the parameter set
PARTIALSSHCOMACCESSUSER<k>, then the user has full SSHCOM access.
•
If a user is included in parameter sets PARTIALSSHCOMACCESSGROUP<n> as well as sets
FULLSSHCOMACCESSUSER<i> or FULLSSHCOMACCESSGROUP<j>, then the user has full SSHCOM
access.
See also:
•
PARTIALSSHCOMACCESSGROUP<n>, FULLSSHCOMACCESSUSER<i>,
FULLSSHCOMACCESSGROUP<j>, LIFECYCLEPOLICYPUBLICUSERKEY
•
See table in “
SSHCOM Access Summary
” in section "SSHCOM Command Reference".
PORT
Use this parameter to specify the port number a SSH2 server should listen on for incoming connections.
Parameter Syntax
PORT
number
Arguments
number
Refers to the decimal number of a TCP/IP port.
Default
The default for this parameter is 22.
Considerations
•
The ICANN manages a list of "well-known" port numbers for various protocols (see
http://www.iana.org/assignments/port-numbers
). 22 is the well-known port for the SSH protocol.
•
The choice for the port value in your specific environment will depend on the applications already running on
your NonStop systems, the ports in use, and your firewall configuration.
PTCPIPFILTERKEY
Use this parameter to specify a filter key to enable round-robin filtering with parallel library TCP/IP or TCP/IPV6.
Parameter Syntax
PTCPIPFILTERKEY
password
| *
Arguments
password
A password that serves as a key to enable round-robin filtering of multiple instances of SSH2 servers listening
on the same port. The password will override the value of the DEFINE =PTCPIP^FILTER^KEY, which may
have been passed to SSH2 at startup.
*
Содержание NonStop SSH 544701-014
Страница 12: ...xii Contents HP NonStop SSH Reference Manual ...
Страница 24: ...24 Preface HP NonStop SSH Reference Manual ...
Страница 30: ...30 Introduction HP NonStop SSH Reference Manual ...
Страница 46: ...46 Installation Quick Start HP NonStop SSH Reference Manual ...
Страница 132: ...132 The SSH User Database HP NonStop SSH Reference Manual ...
Страница 214: ...214 SSH and SFTP Client Reference HP NonStop SSH Reference Manual ...
Страница 278: ...278 STN Reference HP NonStop SSH Reference Manual ...
Страница 298: ...298 Monitoring and Auditing HP NonStop SSH Reference Manual ...
Страница 302: ...302 Performance Considerations HP NonStop SSH Reference Manual ...