Annotation of src/usr.bin/ssh/ssh-add.1, Revision 1.17
1.1 deraadt 1: .\" -*- nroff -*-
2: .\"
3: .\" Author: Tatu Ylonen <ylo@cs.hut.fi>
4: .\" Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
5: .\" All rights reserved
6: .\"
1.17 ! deraadt 7: .\" As far as I am concerned, the code I have written for this software
! 8: .\" can be used freely for any purpose. Any derived versions of this
! 9: .\" software must be clearly marked as such, and if the derived work is
! 10: .\" incompatible with the protocol description in the RFC file, it must be
! 11: .\" called by a name other than "ssh" or "Secure Shell".
! 12: .\"
! 13: .\"
! 14: .\" Copyright (c) 1999,2000 Markus Friedl. All rights reserved.
! 15: .\" Copyright (c) 1999 Aaron Campbell. All rights reserved.
! 16: .\" Copyright (c) 1999 Theo de Raadt. All rights reserved.
! 17: .\"
! 18: .\" Redistribution and use in source and binary forms, with or without
! 19: .\" modification, are permitted provided that the following conditions
! 20: .\" are met:
! 21: .\" 1. Redistributions of source code must retain the above copyright
! 22: .\" notice, this list of conditions and the following disclaimer.
! 23: .\" 2. Redistributions in binary form must reproduce the above copyright
! 24: .\" notice, this list of conditions and the following disclaimer in the
! 25: .\" documentation and/or other materials provided with the distribution.
1.1 deraadt 26: .\"
1.17 ! deraadt 27: .\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
! 28: .\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
! 29: .\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
! 30: .\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
! 31: .\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
! 32: .\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
! 33: .\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
! 34: .\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
! 35: .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
! 36: .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
1.1 deraadt 37: .\"
1.2 deraadt 38: .Dd September 25, 1999
39: .Dt SSH-ADD 1
40: .Os
41: .Sh NAME
42: .Nm ssh-add
1.14 markus 43: .Nd adds RSA or DSA identities for the authentication agent
1.2 deraadt 44: .Sh SYNOPSIS
45: .Nm ssh-add
1.7 markus 46: .Op Fl lLdD
1.2 deraadt 47: .Op Ar
1.12 aaron 48: .Sh DESCRIPTION
1.2 deraadt 49: .Nm
1.14 markus 50: adds RSA or DSA identities to the authentication agent,
1.2 deraadt 51: .Xr ssh-agent 1 .
1.1 deraadt 52: When run without arguments, it adds the file
1.2 deraadt 53: .Pa $HOME/.ssh/identity .
1.11 aaron 54: Alternative file names can be given on the command line.
55: If any file requires a passphrase,
1.2 deraadt 56: .Nm
1.12 aaron 57: asks for the passphrase from the user.
1.11 aaron 58: The Passphrase it is read from the user's tty.
1.2 deraadt 59: .Pp
1.1 deraadt 60: The authentication agent must be running and must be an ancestor of
61: the current process for
1.2 deraadt 62: .Nm
1.1 deraadt 63: to work.
1.2 deraadt 64: .Pp
65: The options are as follows:
66: .Bl -tag -width Ds
67: .It Fl l
1.7 markus 68: Lists fingerprints of all identities currently represented by the agent.
69: .It Fl L
70: Lists public key parameters of all identities currently represented by the agent.
1.2 deraadt 71: .It Fl d
1.1 deraadt 72: Instead of adding the identity, removes the identity from the agent.
1.2 deraadt 73: .It Fl D
1.1 deraadt 74: Deletes all identities from the agent.
1.2 deraadt 75: .El
76: .Sh FILES
77: .Bl -tag -width Ds
1.9 markus 78: .It Pa $HOME/.ssh/identity
1.11 aaron 79: Contains the RSA authentication identity of the user.
80: This file should not be readable by anyone but the user.
1.4 markus 81: Note that
82: .Nm
83: ignores this file if it is accessible by others.
84: It is possible to
1.1 deraadt 85: specify a passphrase when generating the key; that passphrase will be
1.11 aaron 86: used to encrypt the private part of this file.
87: This is the default file added by
1.2 deraadt 88: .Nm
1.1 deraadt 89: when no other files have been specified.
1.14 markus 90: .It Pa $HOME/.ssh/id_dsa
91: Contains the DSA authentication identity of the user.
1.16 itojun 92: .El
1.9 markus 93: .Sh ENVIRONMENT
94: .Bl -tag -width Ds
95: .It Ev "DISPLAY" and "SSH_ASKPASS"
1.1 deraadt 96: If
1.2 deraadt 97: .Nm
1.1 deraadt 98: needs a passphrase, it will read the passphrase from the current
1.11 aaron 99: terminal if it was run from a terminal.
100: If
1.2 deraadt 101: .Nm
1.1 deraadt 102: does not have a terminal associated with it but
1.2 deraadt 103: .Ev DISPLAY
1.8 markus 104: and
105: .Ev SSH_ASKPASS
106: are set, it will execute the program specified by
107: .Ev SSH_ASKPASS
1.11 aaron 108: and open an X11 window to read the passphrase.
109: This is particularly useful when calling
1.2 deraadt 110: .Nm
111: from a
112: .Pa .Xsession
1.11 aaron 113: or related script.
114: (Note that on some machines it
1.2 deraadt 115: may be necessary to redirect the input from
116: .Pa /dev/null
117: to make this work.)
1.16 itojun 118: .El
1.2 deraadt 119: .Sh AUTHOR
1.1 deraadt 120: Tatu Ylonen <ylo@cs.hut.fi>
1.3 deraadt 121: .Pp
1.5 deraadt 122: OpenSSH
123: is a derivative of the original (free) ssh 1.2.12 release, but with bugs
1.11 aaron 124: removed and newer features re-added.
125: Rapidly after the 1.2.12 release,
126: newer versions bore successively more restrictive licenses.
127: This version of OpenSSH
1.5 deraadt 128: .Bl -bullet
129: .It
1.10 aaron 130: has all components of a restrictive nature (i.e., patents, see
1.5 deraadt 131: .Xr ssl 8 )
132: directly removed from the source code; any licensed or patented components
133: are chosen from
134: external libraries.
135: .It
136: has been updated to support ssh protocol 1.5.
137: .It
1.12 aaron 138: contains added support for
1.5 deraadt 139: .Xr kerberos 8
140: authentication and ticket passing.
141: .It
142: supports one-time password authentication with
143: .Xr skey 1 .
144: .El
1.2 deraadt 145: .Sh SEE ALSO
146: .Xr ssh 1 ,
147: .Xr ssh-agent 1 ,
148: .Xr ssh-keygen 1 ,
1.3 deraadt 149: .Xr sshd 8 ,
150: .Xr ssl 8