Package org.apache.sshd.core
Class CoreModuleProperties
- java.lang.Object
-
- org.apache.sshd.core.CoreModuleProperties
-
public final class CoreModuleProperties extends Object
Configurable properties for sshd-core.- Author:
- Apache MINA SSHD Project
-
-
Field Summary
Fields Modifier and Type Field Description static Property<Boolean>
ABORT_ON_INVALID_CERTIFICATE
Defines if we should abort in case we encounter an invalid (e.g.static String
AGENT_FORWARDING_TYPE
The request type of agent forwarding.static String
AGENT_FORWARDING_TYPE_IETF
The agent forwarding type defined by IETF (https://tools.ietf.org/html/draft-ietf-secsh-agent-02).static String
AGENT_FORWARDING_TYPE_OPENSSH
The agent forwarding type defined by OpenSSH.static Property<Boolean>
ALLOW_DHG1_KEX_FALLBACK
Whether allowed to fall back to DH group with SHA-1 KEX if exhausted all available primes for SHA-256.static Property<Boolean>
ASYNC_SERVER_STDERR_CHUNK_BELOW_WINDOW_SIZE
If should chunk data sent viaChannelAsyncOutputStream
when reported remote STDERR stream window size is less than its packet sizestatic Property<Boolean>
ASYNC_SERVER_STDOUT_CHUNK_BELOW_WINDOW_SIZE
If should chunk data sent viaChannelAsyncOutputStream
when reported remote STDOUT stream window size is less than its packet sizestatic Property<String>
AUTH_METHODS
This key is used when configuring multi-step authentications.static Property<Duration>
AUTH_SOCKET_TIMEOUT
Property that can be set on theSession
in order to control the authentication timeout (millis).static Property<Duration>
AUTH_TIMEOUT
Key used to retrieve the value of the timeout after which it will close the connection if the other side has not been authenticated - in milliseconds.static String
AUTO_WELCOME_BANNER_VALUE
Special value that can be set for theWELCOME_BANNER
property indicating that the server should generate a banner consisting of the random art of the server's keys (if any are provided).static Property<Integer>
BUFFER_SIZE
Value used by theInvertedShellWrapper
to control copy buffer size.static Property<Integer>
BUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_SIZE
Key used when creating aBufferedIoOutputStream
in order to specify max.static Property<Duration>
BUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_WAIT
Key used when creating aBufferedIoOutputStream
in order to specify max.static Property<Duration>
CHANNEL_CLOSE_TIMEOUT
Key used to configure the timeout used when writing a close request on a channel.static Property<Duration>
CHANNEL_OPEN_TIMEOUT
Value that can be set on theFactoryManager
or the session to configure the channel open timeout value (millis).static Property<String>
CLIENT_IDENTIFICATION
Key used to retrieve the value of the client identification string.static Property<Duration>
COMMAND_EXIT_TIMEOUT
Key used to configure the timeout used when receiving a close request on a channel to wait until the command cleanly exits after setting an EOF on the input stream.static int
DEFAULT_FORWARDER_BUF_SIZE
static long
DEFAULT_LIMIT_PACKET_SIZE
static long
DEFAULT_MAX_PACKET_SIZE
static long
DEFAULT_WINDOW_SIZE
static Property<Duration>
DISCONNECT_TIMEOUT
Key used to retrieve the value of the disconnect timeout which is used when a disconnection is attempted.static Property<Duration>
FORWARD_REQUEST_TIMEOUT
Used to configure the timeout (milliseconds) for receiving a response for the forwarding requeststatic Property<Integer>
FORWARDER_BUFFER_SIZE
Property that can be set on the factory manager in order to control the buffer size used to forward data from the established channelstatic Property<Duration>
HEARTBEAT_INTERVAL
Key used to set the heartbeat interval in milliseconds (0 to disable = default)static Property<Duration>
HEARTBEAT_REPLY_WAIT
Key used to indicate that the heartbeat request is also expecting a reply - time in milliseconds to wait for the reply.static Property<String>
HEARTBEAT_REQUEST
Key used to check the heartbeat request that should be sent to the serverstatic Property<Duration>
IDLE_TIMEOUT
Key used to retrieve the value of idle timeout after which it will close the connection - in milliseconds.static Property<Boolean>
IGNORE_INVALID_IDENTITIES
Whether to ignore invalid identities files when pre-initializing the client sessionstatic Property<Long>
IGNORE_MESSAGE_FREQUENCY
Average number of packets to be skipped before anSSH_MSG_IGNORE
message is inserted in the stream.static Property<Integer>
IGNORE_MESSAGE_SIZE
Minimum size ofSSH_MSG_IGNORE
payload to send if feature enabled.static Property<Integer>
IGNORE_MESSAGE_VARIANCE
The variance to be used around the configuredIGNORE_MESSAGE_FREQUENCY
value in order to avoid insertion at a set frequency.static Property<Integer>
INPUT_STREAM_PUMP_CHUNK_SIZE
On some platforms, a call to always throws anIOException
.static Property<String>
INTERACTIVE_LANGUAGE_TAG
As per RFC-4256: The language tag is deprecated and SHOULD be the empty string.static Property<String>
INTERACTIVE_SUBMETHODS
As per RFC-4256: The submethods field is included so the user can give a hint of which actual methods to use.static Property<Boolean>
KB_SERVER_INTERACTIVE_ECHO_PROMPT
static Property<String>
KB_SERVER_INTERACTIVE_INSTRUCTION
static Property<String>
KB_SERVER_INTERACTIVE_LANG
static Property<String>
KB_SERVER_INTERACTIVE_NAME
static Property<String>
KB_SERVER_INTERACTIVE_PROMPT
static Property<Duration>
KEX_PROPOSAL_SETUP_TIMEOUT
If the peer initiates a key exchange, we send our own KEX_INIT message with the proposal.static Property<Long>
LIMIT_PACKET_SIZE
A safety value that is designed to avoid an attack that uses large channel packet sizesstatic Property<Integer>
MAX_AUTH_REQUESTS
Key used to retrieve the value in the configuration properties map of the maximum number of failed authentication requests before the server closes the connection.static Property<Integer>
MAX_CONCURRENT_CHANNELS
Property that can be used to configure max.static Property<Integer>
MAX_CONCURRENT_SESSIONS
Key used to retrieve the value of the maximum concurrent open session count per username.static Property<Integer>
MAX_EXTDATA_BUFSIZE
Maximum amount of extended (a.k.a.static int
MAX_FORWARDER_BUF_SIZE
static Property<Integer>
MAX_IDENTIFICATION_SIZE
Maximum allowed size of the initial identification text sent during the handshakestatic Property<Long>
MAX_PACKET_SIZE
Key used to retrieve the value of the maximum packet size in the configuration properties map.static int
MIN_FORWARDER_BUF_SIZE
static Property<String>
MODULI_URL
A URL pointing to the moduli file.static Property<Integer>
NIO_WORKERS
Number of NIO worker threads to use.static Property<Duration>
NIO2_MIN_WRITE_TIMEOUT
Minimum NIO2 write wait timeout for a single outgoing packet - in millisecondsstatic Property<Integer>
NIO2_READ_BUFFER_SIZE
Read buffer size for NIO2 sessions SeeNio2Session
static Property<Duration>
NIO2_READ_TIMEOUT
Key used to retrieve the value of the socket read timeout for NIO2 session implementation - in milliseconds.static Property<Integer>
PASSWORD_PROMPTS
Specifies the number of interactive prompts before giving up.static Property<Boolean>
PREFER_UNIX_AGENT
static Property<String>
PREFERRED_AUTHS
Ordered comma separated list of authentications methods.static Property<Integer>
PROP_DHGEX_CLIENT_MAX_KEY
static Property<Integer>
PROP_DHGEX_CLIENT_MIN_KEY
static Property<Integer>
PROP_DHGEX_CLIENT_PRF_KEY
static Property<Integer>
PROP_DHGEX_SERVER_MAX_KEY
SeeDHGEXServer
.static Property<Integer>
PROP_DHGEX_SERVER_MIN_KEY
SeeDHGEXServer
.static Property<String>
PROXY_AUTH_CHANNEL_TYPE
Value that can be set in order to control the type of authentication channel being requested when forwarding a PTY session.static Property<String>
PROXY_CHANNEL_TYPE
Value used to configure the type of proxy forwarding channel to be used.static Property<Duration>
PUMP_SLEEP_TIME
Value used by theInvertedShellWrapper
to control the "busy-wait" sleep time (millis) on the pumping loop if nothing was pumped - must be positive.static Property<Long>
REKEY_BLOCKS_LIMIT
Key re-exchange will be automatically performed after the specified number of cipher blocks has been processed - positive 64-bit value.static Property<Long>
REKEY_BYTES_LIMIT
Key re-exchange will be automatically performed after the session has sent or received the given amount of bytes.static Property<Long>
REKEY_PACKETS_LIMIT
Key re-exchange will be automatically performed after the specified number of packets has been exchanged - positive 64-bit value.static Property<Duration>
REKEY_TIME_LIMIT
Key re-exchange will be automatically performed after the specified amount of time has elapsed since the last key exchange - in milliseconds.static Property<Boolean>
REQUEST_EXEC_REPLY
Configure whether reply for the "exec" request is requiredstatic Property<Boolean>
REQUEST_SHELL_REPLY
Configure whether reply for the "shell" request is requiredstatic Property<Boolean>
REQUEST_SUBSYSTEM_REPLY
Configure whether reply for the "subsystem&quoot; request is requiredstatic Property<Boolean>
SEND_IMMEDIATE_IDENTIFICATION
Whether to send the identification string immediately upon session connection being established or wait for the server's identification before sending our own.static Property<Boolean>
SEND_IMMEDIATE_KEXINIT
Whether to sendSSH_MSG_KEXINIT
immediately after sending the client identification string or wait until the severer's one has been received.static Property<Boolean>
SEND_REPLY_FOR_CHANNEL_DATA
RFC4254 does not clearly specify how to handleSSH_MSG_CHANNEL_DATA
andSSH_MSG_CHANNEL_EXTENDED_DATA
received through an unknown channel.static char
SERVER_EXTRA_IDENT_LINES_SEPARATOR
Separator used in theSERVER_EXTRA_IDENTIFICATION_LINES
configuration string to indicate new line breakstatic Property<String>
SERVER_EXTRA_IDENTIFICATION_LINES
Key used to retrieve any extra lines to be sent during initial protocol handshake before the identification.static Property<String>
SERVER_IDENTIFICATION
Key used to retrieve the value of the server identification string.static Property<Integer>
SOCKET_BACKLOG
Socket backlog.static Property<Boolean>
SOCKET_KEEPALIVE
Socket keep-alive.static Property<Integer>
SOCKET_LINGER
Socket linger.static Property<Integer>
SOCKET_RCVBUF
Socket receive buffer size.static Property<Boolean>
SOCKET_REUSEADDR
Socket reuse address.static Property<Integer>
SOCKET_SNDBUF
Socket send buffer size.static Property<Duration>
STOP_WAIT_TIME
Timeout (milliseconds) to wait for client / server stop request if immediate stop requested.static Property<Boolean>
TCP_NODELAY
Socket tcp no-delay.static Property<Duration>
WAIT_FOR_SPACE_TIMEOUT
Configure max.static Property<Object>
WELCOME_BANNER
Key used to retrieve the value of welcome banner that will be displayed when a user connects to the server.static Property<Charset>
WELCOME_BANNER_CHARSET
The charset to use if the configured welcome banner points to a file - if not specified (either as a string or aCharset
then the local default is used.static Property<String>
WELCOME_BANNER_LANGUAGE
Key used to denote the language code for the welcome banner (if such a banner is configured).static Property<WelcomeBannerPhase>
WELCOME_BANNER_PHASE
TheWelcomeBannerPhase
value - either as an enum or a stringstatic Property<Long>
WINDOW_SIZE
Key used to retrieve the value of the channel window size in the configuration properties map.static Property<Duration>
WINDOW_TIMEOUT
Key used to retrieve timeout (msec.) to wait for data to become available when reading from a channel.static Property<Integer>
X11_BASE_PORT
Configuration value for theX11ForwardSupport
to control the base port number for the X11 display number socket binding.static Property<String>
X11_BIND_HOST
Configuration value for theX11ForwardSupport
to control the host used to bind to for the X11 display when looking for a free port.static Property<Integer>
X11_DISPLAY_OFFSET
Configuration value for theX11ForwardSupport
to control from which X11 display number to start looking for a free value.static Property<Integer>
X11_MAX_DISPLAYS
Configuration value for theX11ForwardSupport
to control up to which (but not including) X11 display number to look or a free value.static Property<Duration>
X11_OPEN_TIMEOUT
Configuration value for theX11ForwardSupport
to control the channel open timeout.
-
-
-
Field Detail
-
PROXY_AUTH_CHANNEL_TYPE
public static final Property<String> PROXY_AUTH_CHANNEL_TYPE
Value that can be set in order to control the type of authentication channel being requested when forwarding a PTY session.
-
CHANNEL_OPEN_TIMEOUT
public static final Property<Duration> CHANNEL_OPEN_TIMEOUT
Value that can be set on theFactoryManager
or the session to configure the channel open timeout value (millis).
-
PROXY_CHANNEL_TYPE
public static final Property<String> PROXY_CHANNEL_TYPE
Value used to configure the type of proxy forwarding channel to be used. See also https://tools.ietf.org/html/draft-ietf-secsh-agent-02
-
AUTH_SOCKET_TIMEOUT
public static final Property<Duration> AUTH_SOCKET_TIMEOUT
Property that can be set on theSession
in order to control the authentication timeout (millis).
-
DEFAULT_FORWARDER_BUF_SIZE
public static final int DEFAULT_FORWARDER_BUF_SIZE
- See Also:
- Constant Field Values
-
MIN_FORWARDER_BUF_SIZE
public static final int MIN_FORWARDER_BUF_SIZE
- See Also:
- Constant Field Values
-
MAX_FORWARDER_BUF_SIZE
public static final int MAX_FORWARDER_BUF_SIZE
- See Also:
- Constant Field Values
-
FORWARDER_BUFFER_SIZE
public static final Property<Integer> FORWARDER_BUFFER_SIZE
Property that can be set on the factory manager in order to control the buffer size used to forward data from the established channel
-
PREFERRED_AUTHS
public static final Property<String> PREFERRED_AUTHS
Ordered comma separated list of authentications methods. Authentications methods accepted by the server will be tried in the given order. If not configured ornull
/empty, then the session'sUserAuthFactoriesManager.getUserAuthFactories()
is used as-is
-
PASSWORD_PROMPTS
public static final Property<Integer> PASSWORD_PROMPTS
Specifies the number of interactive prompts before giving up. The argument to this keyword must be an integer.
-
CLIENT_IDENTIFICATION
public static final Property<String> CLIENT_IDENTIFICATION
Key used to retrieve the value of the client identification string. If set, then it is appended to the (standard) "SSH-2.0-" prefix. Otherwise a default is sent that consists of "SSH-2.0-" plus the current SSHD artifact name and version in uppercase - e.g., "SSH-2.0-APACHE-SSHD-1.0.0"
-
SEND_IMMEDIATE_IDENTIFICATION
public static final Property<Boolean> SEND_IMMEDIATE_IDENTIFICATION
Whether to send the identification string immediately upon session connection being established or wait for the server's identification before sending our own.
-
SEND_IMMEDIATE_KEXINIT
public static final Property<Boolean> SEND_IMMEDIATE_KEXINIT
Whether to sendSSH_MSG_KEXINIT
immediately after sending the client identification string or wait until the severer's one has been received.- See Also:
SEND_IMMEDIATE_IDENTIFICATION
-
ALLOW_DHG1_KEX_FALLBACK
public static final Property<Boolean> ALLOW_DHG1_KEX_FALLBACK
Whether allowed to fall back to DH group with SHA-1 KEX if exhausted all available primes for SHA-256.
-
KEX_PROPOSAL_SETUP_TIMEOUT
public static final Property<Duration> KEX_PROPOSAL_SETUP_TIMEOUT
If the peer initiates a key exchange, we send our own KEX_INIT message with the proposal. This is a last-resort timeout for waiting until we have prepared our own KEX proposal. This timeout should actually never be hit unless there is a serious deadlock somewhere and the session is never closed. It should be set to a reasonably high value; it must be at least 5 seconds and the default is 42 seconds. If the timeout is ever hit, the key exchange initiated by the peer will fail.
-
HEARTBEAT_INTERVAL
public static final Property<Duration> HEARTBEAT_INTERVAL
Key used to set the heartbeat interval in milliseconds (0 to disable = default)
-
HEARTBEAT_REQUEST
public static final Property<String> HEARTBEAT_REQUEST
Key used to check the heartbeat request that should be sent to the server
-
HEARTBEAT_REPLY_WAIT
public static final Property<Duration> HEARTBEAT_REPLY_WAIT
Key used to indicate that the heartbeat request is also expecting a reply - time in milliseconds to wait for the reply. If non-positive then no reply is expected (nor requested).
-
IGNORE_INVALID_IDENTITIES
public static final Property<Boolean> IGNORE_INVALID_IDENTITIES
Whether to ignore invalid identities files when pre-initializing the client session
-
ABORT_ON_INVALID_CERTIFICATE
public static final Property<Boolean> ABORT_ON_INVALID_CERTIFICATE
Defines if we should abort in case we encounter an invalid (e.g. expired) openssh certificate.
-
INTERACTIVE_LANGUAGE_TAG
public static final Property<String> INTERACTIVE_LANGUAGE_TAG
As per RFC-4256: The language tag is deprecated and SHOULD be the empty string. It may be removed in a future revision of this specification. Instead, the server SHOULD select the language to be used based on the tags communicated during key exchange
-
INTERACTIVE_SUBMETHODS
public static final Property<String> INTERACTIVE_SUBMETHODS
As per RFC-4256: The submethods field is included so the user can give a hint of which actual methods to use. It is a comma-separated list of authentication submethods (software or hardware) that the user prefers. If the client has knowledge of the submethods preferred by the user, presumably through a configuration setting, it MAY use the submethods field to pass this information to the server. Otherwise, it MUST send the empty string. The actual names of the submethods is something the user and the server need to agree upon. Server interpretation of the submethods field is implementation- dependent.
-
REQUEST_EXEC_REPLY
public static final Property<Boolean> REQUEST_EXEC_REPLY
Configure whether reply for the "exec" request is required
-
INPUT_STREAM_PUMP_CHUNK_SIZE
public static final Property<Integer> INPUT_STREAM_PUMP_CHUNK_SIZE
On some platforms, a call to always throws anIOException
. So we need to protect against that and chunk the call into smaller calls. This problem was found on Windows, JDK 1.6.0_03-b05.
-
REQUEST_SHELL_REPLY
public static final Property<Boolean> REQUEST_SHELL_REPLY
Configure whether reply for the "shell" request is required
-
REQUEST_SUBSYSTEM_REPLY
public static final Property<Boolean> REQUEST_SUBSYSTEM_REPLY
Configure whether reply for the "subsystem&quoot; request is requiredDefault value for
REQUEST_SUBSYSTEM_REPLY
- according to RFC4254 section 6.5:It is RECOMMENDED that the reply to these messages be requested and checked.
-
ASYNC_SERVER_STDOUT_CHUNK_BELOW_WINDOW_SIZE
public static final Property<Boolean> ASYNC_SERVER_STDOUT_CHUNK_BELOW_WINDOW_SIZE
If should chunk data sent viaChannelAsyncOutputStream
when reported remote STDOUT stream window size is less than its packet size- See Also:
- SSHD-1123
-
ASYNC_SERVER_STDERR_CHUNK_BELOW_WINDOW_SIZE
public static final Property<Boolean> ASYNC_SERVER_STDERR_CHUNK_BELOW_WINDOW_SIZE
If should chunk data sent viaChannelAsyncOutputStream
when reported remote STDERR stream window size is less than its packet size- See Also:
- SSHD-1123
-
DEFAULT_WINDOW_SIZE
public static final long DEFAULT_WINDOW_SIZE
- See Also:
- Constant Field Values
-
WINDOW_SIZE
public static final Property<Long> WINDOW_SIZE
Key used to retrieve the value of the channel window size in the configuration properties map.
-
WINDOW_TIMEOUT
public static final Property<Duration> WINDOW_TIMEOUT
Key used to retrieve timeout (msec.) to wait for data to become available when reading from a channel. If not set or non-positive then infinite value is assumed
-
BUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_SIZE
public static final Property<Integer> BUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_SIZE
Key used when creating aBufferedIoOutputStream
in order to specify max. allowed unwritten pending bytes. If this value is exceeded then the code waits up toBUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_WAIT
for the pending data to be written and thus make room for the new request.
-
BUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_WAIT
public static final Property<Duration> BUFFERED_IO_OUTPUT_MAX_PENDING_WRITE_WAIT
Key used when creating aBufferedIoOutputStream
in order to specify max. wait time (msec.) for pending writes to be completed before enqueuing a new request
-
DEFAULT_MAX_PACKET_SIZE
public static final long DEFAULT_MAX_PACKET_SIZE
- See Also:
- Constant Field Values
-
MAX_PACKET_SIZE
public static final Property<Long> MAX_PACKET_SIZE
Key used to retrieve the value of the maximum packet size in the configuration properties map.
-
DEFAULT_LIMIT_PACKET_SIZE
public static final long DEFAULT_LIMIT_PACKET_SIZE
- See Also:
- Constant Field Values
-
LIMIT_PACKET_SIZE
public static final Property<Long> LIMIT_PACKET_SIZE
A safety value that is designed to avoid an attack that uses large channel packet sizes
-
AUTH_TIMEOUT
public static final Property<Duration> AUTH_TIMEOUT
Key used to retrieve the value of the timeout after which it will close the connection if the other side has not been authenticated - in milliseconds.
-
IDLE_TIMEOUT
public static final Property<Duration> IDLE_TIMEOUT
Key used to retrieve the value of idle timeout after which it will close the connection - in milliseconds.
-
NIO2_READ_TIMEOUT
public static final Property<Duration> NIO2_READ_TIMEOUT
Key used to retrieve the value of the socket read timeout for NIO2 session implementation - in milliseconds.
-
NIO2_MIN_WRITE_TIMEOUT
public static final Property<Duration> NIO2_MIN_WRITE_TIMEOUT
Minimum NIO2 write wait timeout for a single outgoing packet - in milliseconds
-
DISCONNECT_TIMEOUT
public static final Property<Duration> DISCONNECT_TIMEOUT
Key used to retrieve the value of the disconnect timeout which is used when a disconnection is attempted. If the disconnect message has not been sent before the timeout, the underlying socket will be forcibly closed - in milliseconds.
-
CHANNEL_CLOSE_TIMEOUT
public static final Property<Duration> CHANNEL_CLOSE_TIMEOUT
Key used to configure the timeout used when writing a close request on a channel. If the message can not be written before the specified timeout elapses, the channel will be immediately closed. In milliseconds.
-
STOP_WAIT_TIME
public static final Property<Duration> STOP_WAIT_TIME
Timeout (milliseconds) to wait for client / server stop request if immediate stop requested.
-
SOCKET_BACKLOG
public static final Property<Integer> SOCKET_BACKLOG
Socket backlog. SeeAsynchronousServerSocketChannel.bind(java.net.SocketAddress, int)
-
SOCKET_KEEPALIVE
public static final Property<Boolean> SOCKET_KEEPALIVE
Socket keep-alive. SeeStandardSocketOptions.SO_KEEPALIVE
-
SOCKET_SNDBUF
public static final Property<Integer> SOCKET_SNDBUF
Socket send buffer size. SeeStandardSocketOptions.SO_SNDBUF
-
SOCKET_RCVBUF
public static final Property<Integer> SOCKET_RCVBUF
Socket receive buffer size. SeeStandardSocketOptions.SO_RCVBUF
-
SOCKET_REUSEADDR
public static final Property<Boolean> SOCKET_REUSEADDR
Socket reuse address. SeeStandardSocketOptions.SO_REUSEADDR
-
SOCKET_LINGER
public static final Property<Integer> SOCKET_LINGER
Socket linger. SeeStandardSocketOptions.SO_LINGER
-
TCP_NODELAY
public static final Property<Boolean> TCP_NODELAY
Socket tcp no-delay. SeeStandardSocketOptions.TCP_NODELAY
-
NIO2_READ_BUFFER_SIZE
public static final Property<Integer> NIO2_READ_BUFFER_SIZE
Read buffer size for NIO2 sessions SeeNio2Session
-
MAX_IDENTIFICATION_SIZE
public static final Property<Integer> MAX_IDENTIFICATION_SIZE
Maximum allowed size of the initial identification text sent during the handshake
-
REKEY_BYTES_LIMIT
public static final Property<Long> REKEY_BYTES_LIMIT
Key re-exchange will be automatically performed after the session has sent or received the given amount of bytes. If non-positive, then disabled.
-
REKEY_TIME_LIMIT
public static final Property<Duration> REKEY_TIME_LIMIT
Key re-exchange will be automatically performed after the specified amount of time has elapsed since the last key exchange - in milliseconds. If non-positive then disabled.- See Also:
- RFC4253 section 9
-
REKEY_PACKETS_LIMIT
public static final Property<Long> REKEY_PACKETS_LIMIT
Key re-exchange will be automatically performed after the specified number of packets has been exchanged - positive 64-bit value. If non-positive then disabled.- See Also:
- RFC4344 section 3.1
-
REKEY_BLOCKS_LIMIT
public static final Property<Long> REKEY_BLOCKS_LIMIT
Key re-exchange will be automatically performed after the specified number of cipher blocks has been processed - positive 64-bit value. If non-positive then disabled. The default is calculated according to RFC4344 section 3.2
-
IGNORE_MESSAGE_FREQUENCY
public static final Property<Long> IGNORE_MESSAGE_FREQUENCY
Average number of packets to be skipped before anSSH_MSG_IGNORE
message is inserted in the stream. If non-positive, then feature is disabled- See Also:
IGNORE_MESSAGE_VARIANCE
, RFC4251 section 9.3.1
-
IGNORE_MESSAGE_VARIANCE
public static final Property<Integer> IGNORE_MESSAGE_VARIANCE
The variance to be used around the configuredIGNORE_MESSAGE_FREQUENCY
value in order to avoid insertion at a set frequency. If zero, then exact frequency is used. If negative, then the absolute value is used. If greater or equal to the frequency, then assumed to be zero - i.e., no variance- See Also:
- RFC4251 section 9.3.1
-
IGNORE_MESSAGE_SIZE
public static final Property<Integer> IGNORE_MESSAGE_SIZE
Minimum size ofSSH_MSG_IGNORE
payload to send if feature enabled. If non-positive then no message is sent. Otherwise, the actual size is between this size and twice its value- See Also:
- RFC4251 section 9.3.1
-
AGENT_FORWARDING_TYPE
public static final String AGENT_FORWARDING_TYPE
The request type of agent forwarding. The value may be "auth-agent-req" or "[email protected]".- See Also:
- Constant Field Values
-
AGENT_FORWARDING_TYPE_IETF
public static final String AGENT_FORWARDING_TYPE_IETF
The agent forwarding type defined by IETF (https://tools.ietf.org/html/draft-ietf-secsh-agent-02).- See Also:
- Constant Field Values
-
AGENT_FORWARDING_TYPE_OPENSSH
public static final String AGENT_FORWARDING_TYPE_OPENSSH
The agent forwarding type defined by OpenSSH.- See Also:
- Constant Field Values
-
WAIT_FOR_SPACE_TIMEOUT
public static final Property<Duration> WAIT_FOR_SPACE_TIMEOUT
Configure max. wait time (millis) to wait for space to become available
-
FORWARD_REQUEST_TIMEOUT
public static final Property<Duration> FORWARD_REQUEST_TIMEOUT
Used to configure the timeout (milliseconds) for receiving a response for the forwarding request
-
MAX_CONCURRENT_CHANNELS
public static final Property<Integer> MAX_CONCURRENT_CHANNELS
Property that can be used to configure max. allowed concurrent active channels
-
SEND_REPLY_FOR_CHANNEL_DATA
public static final Property<Boolean> SEND_REPLY_FOR_CHANNEL_DATA
RFC4254 does not clearly specify how to handleSSH_MSG_CHANNEL_DATA
andSSH_MSG_CHANNEL_EXTENDED_DATA
received through an unknown channel. Therefore, we provide a configurable approach to it with the default set to ignore it.
-
MAX_AUTH_REQUESTS
public static final Property<Integer> MAX_AUTH_REQUESTS
Key used to retrieve the value in the configuration properties map of the maximum number of failed authentication requests before the server closes the connection.
-
WELCOME_BANNER
public static final Property<Object> WELCOME_BANNER
Key used to retrieve the value of welcome banner that will be displayed when a user connects to the server. Ifnull
/empty then no banner will be sent. The value can be one of the following:- A
File
orPath
, in which case its contents will be transmitted. Note: if the file is empty or does not exits, no banner will be transmitted. - A
URI
or a string starting with "file:/", in which case it will be converted to aPath
and handled accordingly. - A string containing a special value indicator - e.g.,
AUTO_WELCOME_BANNER_VALUE
, in which case the relevant banner content will be generated. - Any other object whose
toString()
value yields a non empty string will be used as the banner contents.
- See Also:
- RFC-4252 section 5.4
- A
-
AUTO_WELCOME_BANNER_VALUE
public static final String AUTO_WELCOME_BANNER_VALUE
Special value that can be set for theWELCOME_BANNER
property indicating that the server should generate a banner consisting of the random art of the server's keys (if any are provided). If no server keys are available, then no banner will be sent- See Also:
- Constant Field Values
-
WELCOME_BANNER_LANGUAGE
public static final Property<String> WELCOME_BANNER_LANGUAGE
Key used to denote the language code for the welcome banner (if such a banner is configured).
-
WELCOME_BANNER_PHASE
public static final Property<WelcomeBannerPhase> WELCOME_BANNER_PHASE
TheWelcomeBannerPhase
value - either as an enum or a string
-
WELCOME_BANNER_CHARSET
public static final Property<Charset> WELCOME_BANNER_CHARSET
The charset to use if the configured welcome banner points to a file - if not specified (either as a string or aCharset
then the local default is used.
-
AUTH_METHODS
public static final Property<String> AUTH_METHODS
This key is used when configuring multi-step authentications. The value needs to be a blank separated list of comma separated list of authentication method names. For example, an argument ofpublickey,password publickey,keyboard-interactive
would require the user to complete public key authentication, followed by either password or keyboard interactive authentication. Only methods that are next in one or more lists are offered at each stage, so for this example, it would not be possible to attempt password or keyboard-interactive authentication before public key.
-
MAX_CONCURRENT_SESSIONS
public static final Property<Integer> MAX_CONCURRENT_SESSIONS
Key used to retrieve the value of the maximum concurrent open session count per username. If not set, then unlimited
-
SERVER_EXTRA_IDENTIFICATION_LINES
public static final Property<String> SERVER_EXTRA_IDENTIFICATION_LINES
Key used to retrieve any extra lines to be sent during initial protocol handshake before the identification. The configured string value should use 124 character to denote line breaks
-
SERVER_EXTRA_IDENT_LINES_SEPARATOR
public static final char SERVER_EXTRA_IDENT_LINES_SEPARATOR
Separator used in theSERVER_EXTRA_IDENTIFICATION_LINES
configuration string to indicate new line break- See Also:
- Constant Field Values
-
SERVER_IDENTIFICATION
public static final Property<String> SERVER_IDENTIFICATION
Key used to retrieve the value of the server identification string. If set, then it is appended to the (standard) "SSH-2.0-" prefix. Otherwise a default is sent that consists of "SSH-2.0-" plus the current SSHD artifact name and version in uppercase - e.g., "SSH-2.0-APACHE-SSHD-1.0.0"
-
COMMAND_EXIT_TIMEOUT
public static final Property<Duration> COMMAND_EXIT_TIMEOUT
Key used to configure the timeout used when receiving a close request on a channel to wait until the command cleanly exits after setting an EOF on the input stream.
-
MODULI_URL
public static final Property<String> MODULI_URL
A URL pointing to the moduli file. If not specified, the default internal file will be used.
-
KB_SERVER_INTERACTIVE_INSTRUCTION
public static final Property<String> KB_SERVER_INTERACTIVE_INSTRUCTION
-
KB_SERVER_INTERACTIVE_ECHO_PROMPT
public static final Property<Boolean> KB_SERVER_INTERACTIVE_ECHO_PROMPT
-
MAX_EXTDATA_BUFSIZE
public static final Property<Integer> MAX_EXTDATA_BUFSIZE
Maximum amount of extended (a.k.a. STDERR) data allowed to be accumulated until aChannelDataReceiver
for the data is registered
-
PROP_DHGEX_SERVER_MIN_KEY
public static final Property<Integer> PROP_DHGEX_SERVER_MIN_KEY
SeeDHGEXServer
.
-
PROP_DHGEX_SERVER_MAX_KEY
public static final Property<Integer> PROP_DHGEX_SERVER_MAX_KEY
SeeDHGEXServer
.
-
PUMP_SLEEP_TIME
public static final Property<Duration> PUMP_SLEEP_TIME
Value used by theInvertedShellWrapper
to control the "busy-wait" sleep time (millis) on the pumping loop if nothing was pumped - must be positive.
-
BUFFER_SIZE
public static final Property<Integer> BUFFER_SIZE
Value used by theInvertedShellWrapper
to control copy buffer size.
-
X11_OPEN_TIMEOUT
public static final Property<Duration> X11_OPEN_TIMEOUT
Configuration value for theX11ForwardSupport
to control the channel open timeout.
-
X11_DISPLAY_OFFSET
public static final Property<Integer> X11_DISPLAY_OFFSET
Configuration value for theX11ForwardSupport
to control from which X11 display number to start looking for a free value.
-
X11_MAX_DISPLAYS
public static final Property<Integer> X11_MAX_DISPLAYS
Configuration value for theX11ForwardSupport
to control up to which (but not including) X11 display number to look or a free value.
-
X11_BASE_PORT
public static final Property<Integer> X11_BASE_PORT
Configuration value for theX11ForwardSupport
to control the base port number for the X11 display number socket binding.
-
X11_BIND_HOST
public static final Property<String> X11_BIND_HOST
Configuration value for theX11ForwardSupport
to control the host used to bind to for the X11 display when looking for a free port.
-
-