5093e42eaa
- upgrade to 7.2p2 - changing license to 2-clause BSD to match source - enable trusted X11 forwarding by default [-X11_trusted_forwarding] - set UID for lastlog properly [-lastlog] - enable use of PAM by default [-enable_PAM_by_default] - copy command line arguments properly [-saveargv-fix] - do not use pthreads in PAM code [-dont_use_pthreads_in_PAM] - fix paths in documentation [-eal3] - prevent race consitions triggered by SIGALRM [-blocksigalrm] - do send and accept locale environment variables by default [-send_locale] - handle hostnames changes during X forwarding [-hostname_changes_when_forwarding_X] - try to remove xauth cookies on exit [-remove_xauth_cookies_on_exit] - properly format pts names for ?tmp? log files [-pts_names_formatting] - check locked accounts when using PAM [-pam_check_locks] - chenge default PermitRootLogin to 'yes' to prevent unwanted surprises on updates from older versions. See README.SUSE for details [-allow_root_password_login] - Disable DH parameters under 2048 bits by default and allow lowering the limit back to the RFC 4419 specified minimum through an option (bsc#932483, bsc#948902) [-disable_short_DH_parameters] - Add getuid() and stat() syscalls to the seccomp filter OBS-URL: https://build.opensuse.org/request/show/398802 OBS-URL: https://build.opensuse.org/package/show/network/openssh?expand=0&rev=103
151 lines
4.1 KiB
Bash
151 lines
4.1 KiB
Bash
#! /bin/sh
|
|
# Copyright (c) 1995-2013 SUSE
|
|
#
|
|
# Author: Jiri Smid <feedback@suse.de>
|
|
#
|
|
# /etc/init.d/sshd
|
|
#
|
|
# and symbolic its link
|
|
#
|
|
# /usr/sbin/rcsshd
|
|
#
|
|
### BEGIN INIT INFO
|
|
# Provides: sshd
|
|
# Required-Start: $network $remote_fs
|
|
# Required-Stop: $network $remote_fs
|
|
# Should-Start: haveged auditd
|
|
# Default-Start: 3 5
|
|
# Default-Stop: 0 1 2 6
|
|
# Description: Start the sshd daemon
|
|
### END INIT INFO
|
|
|
|
SSHD_BIN=/usr/sbin/sshd
|
|
test -x $SSHD_BIN || exit 5
|
|
|
|
SSHD_SYSCONFIG=/etc/sysconfig/ssh
|
|
test -r $SSHD_SYSCONFIG || exit 6
|
|
. $SSHD_SYSCONFIG
|
|
|
|
SSHD_PIDFILE=/var/run/sshd.init.pid
|
|
|
|
. /etc/rc.status
|
|
|
|
# Shell functions sourced from /etc/rc.status:
|
|
# rc_check check and set local and overall rc status
|
|
# rc_status check and set local and overall rc status
|
|
# rc_status -v ditto but be verbose in local rc status
|
|
# rc_status -v -r ditto and clear the local rc status
|
|
# rc_failed set local and overall rc status to failed
|
|
# rc_reset clear local rc status (overall remains)
|
|
# rc_exit exit appropriate to overall rc status
|
|
|
|
function soft_stop () {
|
|
echo -n "Shutting down the listening SSH daemon"
|
|
killproc -p $SSHD_PIDFILE -TERM $SSHD_BIN
|
|
}
|
|
|
|
function force_stop () {
|
|
echo -n "Shutting down SSH daemon *with all active connections*"
|
|
trap '' TERM
|
|
killall sshd 2>/dev/null
|
|
trap - TERM
|
|
}
|
|
|
|
# First reset status of this service
|
|
rc_reset
|
|
|
|
case "$1" in
|
|
start)
|
|
/usr/sbin/sshd-gen-keys-start
|
|
echo -n "Starting SSH daemon"
|
|
## Start daemon with startproc(8). If this fails
|
|
## the echo return value is set appropriate.
|
|
startproc -f -p $SSHD_PIDFILE $SSHD_BIN $SSHD_OPTS -o "PidFile=$SSHD_PIDFILE"
|
|
|
|
# Remember status and be verbose
|
|
rc_status -v
|
|
;;
|
|
stop)
|
|
# If we're shutting down, kill active sshd connections so they're not
|
|
# left hanging.
|
|
runlevel=$(set -- $(runlevel); eval "echo \$$#")
|
|
if [ "x$runlevel" = x0 -o "x$runlevel" = x6 ] ; then
|
|
force_stop
|
|
else
|
|
soft_stop
|
|
fi
|
|
|
|
# Remember status and be verbose
|
|
rc_status -v
|
|
;;
|
|
soft-stop)
|
|
## Stop the listener daemon process with killproc(8) and if this
|
|
## fails set echo the echo return value.
|
|
soft_stop
|
|
|
|
# Remember status and be verbose
|
|
rc_status -v
|
|
;;
|
|
force-stop)
|
|
## stop all running ssh
|
|
force_stop
|
|
|
|
# Remember status and be verbose
|
|
rc_status -v
|
|
;;
|
|
try-restart)
|
|
## Stop the service and if this succeeds (i.e. the
|
|
## service was running before), start it again.
|
|
$0 status >/dev/null && $0 restart
|
|
|
|
# Remember status and be quiet
|
|
rc_status
|
|
;;
|
|
restart)
|
|
## Stop the service without closing live connections
|
|
## and start it again regardless of whether it was
|
|
## running or not
|
|
$0 soft-stop
|
|
$0 start
|
|
|
|
# Remember status and be quiet
|
|
rc_status
|
|
;;
|
|
force-reload|reload)
|
|
## Signal the daemon to reload its config. Most daemons
|
|
## do this on signal 1 (SIGHUP).
|
|
echo -n "Reload service sshd"
|
|
|
|
killproc -p $SSHD_PIDFILE -HUP $SSHD_BIN
|
|
|
|
rc_status -v
|
|
|
|
;;
|
|
status)
|
|
echo -n "Checking for service sshd "
|
|
## Check status with checkproc(8), if process is running
|
|
## checkproc will return with exit status 0.
|
|
|
|
# Status has a slightly different for the status command:
|
|
# 0 - service running
|
|
# 1 - service dead, but /var/run/ pid file exists
|
|
# 2 - service dead, but /var/lock/ lock file exists
|
|
# 3 - service not running
|
|
|
|
checkproc -p $SSHD_PIDFILE $SSHD_BIN
|
|
|
|
rc_status -v
|
|
;;
|
|
probe)
|
|
## Optional: Probe for the necessity of a reload,
|
|
## give out the argument which is required for a reload.
|
|
|
|
test /etc/ssh/sshd_config -nt $SSHD_PIDFILE && echo reload
|
|
;;
|
|
*)
|
|
echo "Usage: $0 {start|stop|soft-stop|force-stop|status|try-restart|restart|force-reload|reload|probe}"
|
|
exit 1
|
|
;;
|
|
esac
|
|
rc_exit
|