clfs-bootstrap

clfs-bootstrap.git
git clone git://git.lenczewski.org/clfs-bootstrap.git
Log | Files | Refs | README | LICENSE

dropbear_config.h (11959B)


      1 #define DROPBEAR_DEFPORT "22"
      2 
      3 /* Listen on all interfaces */
      4 #define DROPBEAR_DEFADDRESS ""
      5 
      6 /* Default hostkey paths - these can be specified on the command line */
      7 #define DSS_PRIV_FILENAME "/etc/dropbear/dropbear_dss_host_key"
      8 #define RSA_PRIV_FILENAME "/etc/dropbear/dropbear_rsa_host_key"
      9 #define ECDSA_PRIV_FILENAME "/etc/dropbear/dropbear_ecdsa_host_key"
     10 #define ED25519_PRIV_FILENAME "/etc/dropbear/dropbear_ed25519_host_key"
     11 
     12 /* Set NON_INETD_MODE if you require daemon functionality (ie Dropbear listens
     13  * on chosen ports and keeps accepting connections. This is the default.
     14  *
     15  * Set INETD_MODE if you want to be able to run Dropbear with inetd (or
     16  * similar), where it will use stdin/stdout for connections, and each process
     17  * lasts for a single connection. Dropbear should be invoked with the -i flag
     18  * for inetd, and can only accept IPv4 connections.
     19  *
     20  * Both of these flags can be defined at once, don't compile without at least
     21  * one of them. */
     22 #define NON_INETD_MODE 1
     23 #define INETD_MODE 1
     24 
     25 /* Include verbose debug output, enabled with -v at runtime. 
     26  * This will add a reasonable amount to your executable size. */
     27 #define DEBUG_TRACE 0
     28 
     29 /* Set this if you want to use the DROPBEAR_SMALL_CODE option. This can save
     30  * several kB in binary size however will make the symmetrical ciphers and hashes
     31  * slower, perhaps by 50%. Recommended for small systems that aren't doing
     32  * much traffic. */
     33 #define DROPBEAR_SMALL_CODE 0
     34 
     35 /* Enable X11 Forwarding - server only */
     36 #define DROPBEAR_X11FWD 0
     37 
     38 /* Enable TCP Fowarding */
     39 /* 'Local' is "-L" style (client listening port forwarded via server)
     40  * 'Remote' is "-R" style (server listening port forwarded via client) */
     41 #define DROPBEAR_CLI_LOCALTCPFWD 1
     42 #define DROPBEAR_CLI_REMOTETCPFWD 1
     43 
     44 #define DROPBEAR_SVR_LOCALTCPFWD 1
     45 #define DROPBEAR_SVR_REMOTETCPFWD 1
     46 
     47 /* Enable Authentication Agent Forwarding */
     48 #define DROPBEAR_SVR_AGENTFWD 1
     49 #define DROPBEAR_CLI_AGENTFWD 1
     50 
     51 /* Note: Both DROPBEAR_CLI_PROXYCMD and DROPBEAR_CLI_NETCAT must be set to
     52  * allow multihop dbclient connections */
     53 
     54 /* Allow using -J <proxycommand> to run the connection through a 
     55    pipe to a program, rather the normal TCP connection */
     56 #define DROPBEAR_CLI_PROXYCMD 1
     57 
     58 /* Enable "Netcat mode" option. This will forward standard input/output
     59  * to a remote TCP-forwarded connection */
     60 #define DROPBEAR_CLI_NETCAT 1
     61 
     62 /* Whether to support "-c" and "-m" flags to choose ciphers/MACs at runtime */
     63 #define DROPBEAR_USER_ALGO_LIST 1
     64 
     65 /* Encryption - at least one required.
     66  * AES128 should be enabled, some very old implementations might only
     67  * support 3DES.
     68  * Including both AES keysize variants (128 and 256) will result in 
     69  * a minimal size increase */
     70 #define DROPBEAR_3DES 0
     71 #define DROPBEAR_TWOFISH128 0
     72 #define DROPBEAR_TWOFISH256 0
     73 #define DROPBEAR_AES128 0
     74 #define DROPBEAR_AES256 1
     75 
     76 /* Enable Chacha20-Poly1305 authenticated encryption mode. This is
     77  * generally faster than AES256 on CPU w/o dedicated AES instructions,
     78  * having the same key size. Recommended.
     79  * Compiling in will add ~5,5kB to binary size on x86-64 */
     80 #define DROPBEAR_CHACHA20POLY1305 1
     81 
     82 /* Enable "Counter Mode" for ciphers. Recommended. */
     83 #define DROPBEAR_ENABLE_CTR_MODE 1
     84 
     85 /* Enable CBC mode for ciphers. This has security issues though
     86    may be required for compatibility with old implementations */
     87 #define DROPBEAR_ENABLE_CBC_MODE 0
     88 
     89 /* Enable "Galois/Counter Mode" for ciphers. This authenticated
     90  * encryption mode is combination of CTR mode and GHASH. Recommended
     91  * for security and forwards compatibility, but slower than CTR on
     92  * CPU w/o dedicated AES/GHASH instructions.
     93  * Compiling in will add ~6kB to binary size on x86-64 */
     94 #define DROPBEAR_ENABLE_GCM_MODE 1
     95 
     96 /* Message integrity. sha2-256 is recommended as a default, 
     97    sha1 for compatibility */
     98 #define DROPBEAR_SHA1_96_HMAC 0
     99 #define DROPBEAR_SHA1_HMAC 0
    100 #define DROPBEAR_SHA2_256_HMAC 1
    101 
    102 /* Hostkey/public key algorithms - at least one required, these are used
    103  * for hostkey as well as for verifying signatures with pubkey auth.
    104  * Removing either of these won't save very much space.
    105  * RSA is recommended
    106  * DSS may be necessary to connect to some systems though
    107    is not recommended for new keys */
    108 #define DROPBEAR_DSS 0
    109 #define DROPBEAR_RSA 1
    110 
    111 /* ECDSA is significantly faster than RSA or DSS. Compiling in ECC
    112  * code (either ECDSA or ECDH) increases binary size - around 30kB
    113  * on x86-64 */
    114 #define DROPBEAR_ECDSA 0
    115 
    116 /* Ed25519 is faster than ECDSA. Compiling in Ed25519 code increases
    117    binary size - around 7,5kB on x86-64 */
    118 #define DROPBEAR_ED25519 1
    119 
    120 /* RSA must be >=1024 */
    121 #define DROPBEAR_DEFAULT_RSA_SIZE 4096
    122 /* DSS is always 1024 */
    123 /* ECDSA defaults to largest size configured, usually 521 */
    124 /* Ed25519 is always 256 */
    125 
    126 /* Add runtime flag "-R" to generate hostkeys as-needed when the first 
    127    connection using that key type occurs.
    128    This avoids the need to otherwise run "dropbearkey" and avoids some problems
    129    with badly seeded /dev/urandom when systems first boot. */
    130 #define DROPBEAR_DELAY_HOSTKEY 1
    131 
    132 
    133 /* Key exchange algorithm.
    134 
    135  * group14_sha1 - 2048 bit, sha1
    136  * group14_sha256 - 2048 bit, sha2-256
    137  * group16 - 4096 bit, sha2-512
    138  * group1 - 1024 bit, sha1
    139  * curve25519 - elliptic curve DH
    140  * ecdh - NIST elliptic curve DH (256, 384, 521)
    141  *
    142  * group1 is too small for security though is necessary if you need 
    143      compatibility with some implementations such as Dropbear versions < 0.53
    144  * group14 is supported by most implementations.
    145  * group16 provides a greater strength level but is slower and increases binary size
    146  * curve25519 and ecdh algorithms are faster than non-elliptic curve methods
    147  * curve25519 increases binary size by ~2,5kB on x86-64
    148  * including either ECDH or ECDSA increases binary size by ~30kB on x86-64
    149 
    150  * Small systems should generally include either curve25519 or ecdh for performance.
    151  * curve25519 is less widely supported but is faster
    152  */ 
    153 
    154 #define DROPBEAR_DH_GROUP1 0
    155 #define DROPBEAR_DH_GROUP14_SHA1 0
    156 #define DROPBEAR_DH_GROUP14_SHA256 1
    157 #define DROPBEAR_DH_GROUP16 1
    158 #define DROPBEAR_ECDH 0
    159 #define DROPBEAR_CURVE25519 1
    160 
    161 /* When group1 is enabled it will only be allowed by Dropbear client
    162 not as a server, due to concerns over its strength. Set to 0 to allow
    163 group1 in Dropbear server too */
    164 #define DROPBEAR_DH_GROUP1_CLIENTONLY 1
    165 
    166 /* Control the memory/performance/compression tradeoff for zlib.
    167  * Set windowBits=8 for least memory usage, see your system's
    168  * zlib.h for full details.
    169  * Default settings (windowBits=15) will use 256kB for compression
    170  * windowBits=8 will use 129kB for compression.
    171  * Both modes will use ~35kB for decompression (using windowBits=15 for
    172  * interoperability) */
    173 #define DROPBEAR_ZLIB_WINDOW_BITS 15 
    174 
    175 /* Whether to do reverse DNS lookups. */
    176 #define DO_HOST_LOOKUP 0
    177 
    178 /* Whether to print the message of the day (MOTD). */
    179 #define DO_MOTD 1
    180 #define MOTD_FILENAME "/etc/motd"
    181 
    182 /* Authentication Types - at least one required.
    183    RFC Draft requires pubkey auth, and recommends password */
    184 #define DROPBEAR_SVR_PASSWORD_AUTH 1
    185 
    186 /* Note: PAM auth is quite simple and only works for PAM modules which just do
    187  * a simple "Login: " "Password: " (you can edit the strings in svr-authpam.c).
    188  * It's useful for systems like OS X where standard password crypts don't work
    189  * but there's an interface via a PAM module. It won't work for more complex
    190  * PAM challenge/response.
    191  * You can't enable both PASSWORD and PAM. */
    192 #define DROPBEAR_SVR_PAM_AUTH 0
    193 
    194 /* ~/.ssh/authorized_keys authentication */
    195 #define DROPBEAR_SVR_PUBKEY_AUTH 1
    196 
    197 /* Whether to take public key options in 
    198  * authorized_keys file into account */
    199 #define DROPBEAR_SVR_PUBKEY_OPTIONS 1
    200 
    201 /* Set this to 0 if your system does not have multiple user support.
    202    (Linux kernel CONFIG_MULTIUSER option)
    203    The resulting binary will not run on a normal system. */
    204 #define DROPBEAR_SVR_MULTIUSER 1
    205 
    206 /* Client authentication options */
    207 #define DROPBEAR_CLI_PASSWORD_AUTH 1
    208 #define DROPBEAR_CLI_PUBKEY_AUTH 1
    209 
    210 /* A default argument for dbclient -i <privatekey>. 
    211 Homedir is prepended unless path begins with / */
    212 #define DROPBEAR_DEFAULT_CLI_AUTHKEY ".ssh/id_dropbear"
    213 
    214 /* Allow specifying the password for dbclient via the DROPBEAR_PASSWORD
    215  * environment variable. */
    216 #define DROPBEAR_USE_PASSWORD_ENV 1
    217 
    218 /* Define this (as well as DROPBEAR_CLI_PASSWORD_AUTH) to allow the use of
    219  * a helper program for the ssh client. The helper program should be
    220  * specified in the SSH_ASKPASS environment variable, and dbclient
    221  * should be run with DISPLAY set and no tty. The program should
    222  * return the password on standard output */
    223 #define DROPBEAR_CLI_ASKPASS_HELPER 0
    224 
    225 /* Save a network roundtrip by sendng a real auth request immediately after
    226  * sending a query for the available methods. This is not yet enabled by default 
    227  since it could cause problems with non-compliant servers */ 
    228 #define DROPBEAR_CLI_IMMEDIATE_AUTH 0
    229 
    230 /* Set this to use PRNGD or EGD instead of /dev/urandom */
    231 #define DROPBEAR_USE_PRNGD 0
    232 #define DROPBEAR_PRNGD_SOCKET "/var/run/dropbear-rng"
    233 
    234 /* Specify the number of clients we will allow to be connected but
    235  * not yet authenticated. After this limit, connections are rejected */
    236 /* The first setting is per-IP, to avoid denial of service */
    237 #define MAX_UNAUTH_PER_IP 5
    238 
    239 /* And then a global limit to avoid chewing memory if connections 
    240  * come from many IPs */
    241 #define MAX_UNAUTH_CLIENTS 30
    242 
    243 /* Default maximum number of failed authentication tries (server option) */
    244 /* -T server option overrides */
    245 #define MAX_AUTH_TRIES 10
    246 
    247 /* The default file to store the daemon's process ID, for shutdown
    248    scripts etc. This can be overridden with the -P flag */
    249 #define DROPBEAR_PIDFILE "/var/run/dropbear.pid"
    250 
    251 /* The command to invoke for xauth when using X11 forwarding.
    252  * "-q" for quiet */
    253 #define XAUTH_COMMAND "/usr/bin/xauth -q"
    254 
    255 
    256 /* if you want to enable running an sftp server (such as the one included with
    257  * OpenSSH), set the path below and set DROPBEAR_SFTPSERVER. 
    258  * The sftp-server program is not provided by Dropbear itself */
    259 #define DROPBEAR_SFTPSERVER 1
    260 #define SFTPSERVER_PATH "/usr/libexec/sftp-server"
    261 
    262 /* This is used by the scp binary when used as a client binary. If you're
    263  * not using the Dropbear client, you'll need to change it */
    264 #define DROPBEAR_PATH_SSH_PROGRAM "/usr/bin/dbclient"
    265 
    266 /* Whether to log commands executed by a client. This only logs the 
    267  * (single) command sent to the server, not what a user did in a 
    268  * shell/sftp session etc. */
    269 #define LOG_COMMANDS 0
    270 
    271 /* Window size limits. These tend to be a trade-off between memory
    272    usage and network performance: */
    273 /* Size of the network receive window. This amount of memory is allocated
    274    as a per-channel receive buffer. Increasing this value can make a
    275    significant difference to network performance. 24kB was empirically
    276    chosen for a 100mbit ethernet network. The value can be altered at
    277    runtime with the -W argument. */
    278 #define DEFAULT_RECV_WINDOW 24576
    279 /* Maximum size of a received SSH data packet - this _MUST_ be >= 32768
    280    in order to interoperate with other implementations */
    281 #define RECV_MAX_PAYLOAD_LEN 32768
    282 /* Maximum size of a transmitted data packet - this can be any value,
    283    though increasing it may not make a significant difference. */
    284 #define TRANS_MAX_PAYLOAD_LEN 16384
    285 
    286 /* Ensure that data is transmitted every KEEPALIVE seconds. This can
    287 be overridden at runtime with -K. 0 disables keepalives */
    288 #define DEFAULT_KEEPALIVE 0
    289 
    290 /* If this many KEEPALIVES are sent with no packets received from the
    291 other side, exit. Not run-time configurable - if you have a need
    292 for runtime configuration please mail the Dropbear list */
    293 #define DEFAULT_KEEPALIVE_LIMIT 3
    294 
    295 /* Ensure that data is received within IDLE_TIMEOUT seconds. This can
    296 be overridden at runtime with -I. 0 disables idle timeouts */
    297 #define DEFAULT_IDLE_TIMEOUT 0
    298 
    299 /* The default path. This will often get replaced by the shell */
    300 #define DEFAULT_PATH "/usr/bin:/bin"