SSH Reference Manual

Document History
Version 4.4
Describes changes in SSH release 97.
Documentation for the following new features has been added:
Added STNCOM/SSHCOM OUT command and STNCOM UAIPADDR command
Changed the range for STNCOM MAX_OPENERS, and the max continuation command length for
STNCOM/SSHCOM.
Added description for new parameter DAEMONMODEOWNERPOLICY controlling access to Daemon mode
commands.
Added description for new USER attribute OWNER allowing actions the same as defined by
PARTIALSSHCOMACCESSUSER/GROUP parameters.
Added additional information for parameter CLIENTMODEOWNERPOLICY.
Added description for new parameters SFTPENHANCEDERRORREPORTING,
PAUTHSUPPRESSIPADDRESS, HOSTKEYTYPE, HOSTKEYBITS and DNSMODE.
Modified description for existing parameters SUBNET, INTERFACE and INTERFACEOUT.
Added section “Multiple IP Process, Multiple IP Address Considerations” and section “TACL Subsystem and
Command Interpreter Configuration”.
Changes in SSH2 release 97 that are incompatible with previous releases:
Processing of ssh EXEC tacl requests changed in case ALLOWED-SUBSYSTEMS does not include tacl. It is
now possible to execute TACL commands or macros even if tacl is not configured in ALLOWED-
SUBSYSTEMS. A TACL subsystem is provided when a user gets a TACL prompt but not when just one TACL
command is executed. In this way it is possible to differentiate between subsystem tacl and use of CI-
PROGRAM. Previously, the execution of CI-PROGRAM via TACL command on the SSH client command line
was rejected if tacl was not an allowed subsystem. The user configuration allows restricting access to TACL
commands via attributes ALLOW-CI, CI-PROGRAM, CI-COMMAND and ALLOW-CI-PROGRAM-
OVERRIDE to an extent that the incompatible change should not cause problems. Please see section “TACL
Subsystem and Command Interpreter Configuration” and check your USER configuration accordingly for those
users that do not have tacl configured in ALLOWED-SUBSYSTEMS.
Version 4.3
Describes changes in SSH2 release 96.
Documentation for the following new features has been added:
Added additional information for parameters AUTOADDAUTHPRINCIPAL and
SFTPREALPATHFILEATTRIBUTEECHOED.
Added section "Controlling SSH and SFTP clients on NonStop via an API".
Explained new USER attribute PTY-SERVER in section "Database for Daemon Mode".
Version 4.2
Describes changes in the SSH2 release 94.
Documentation for the following new features has been added:
Added description for new parameters BURSTSUPPRESSION, EMSBURSTSUPPRESSION,
CONSOLEBURSTSUPPRESSION, FILEBURSTSUPPRESSION, CACHEBURSTSUPPRESSION,
BURSTSUPPRESSIONEXPIRATIONTIME and BURSTSUPPRESSIONMAXLOGLEVEL.
HP NonStop SSH Reference Manual Preface 15