=================================================================== RCS file: /cvsrepo/anoncvs/cvs/src/usr.bin/ssh/sshd_config.5,v retrieving revision 1.184 retrieving revision 1.185 diff -u -r1.184 -r1.185 --- src/usr.bin/ssh/sshd_config.5 2014/12/21 23:35:14 1.184 +++ src/usr.bin/ssh/sshd_config.5 2014/12/22 07:51:30 1.185 @@ -33,8 +33,8 @@ .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. .\" -.\" $OpenBSD: sshd_config.5,v 1.184 2014/12/21 23:35:14 jmc Exp $ -.Dd $Mdocdate: December 21 2014 $ +.\" $OpenBSD: sshd_config.5,v 1.185 2014/12/22 07:51:30 djm Exp $ +.Dd $Mdocdate: December 22 2014 $ .Dt SSHD_CONFIG 5 .Os .Sh NAME @@ -209,6 +209,18 @@ would restrict keyboard interactive authentication to the .Dq bsdauth device. +.Pp +If the +.Dq publickey +method is listed more than one, +.Xr sshd 8 +verifies that keys that have been used successfully are not reused for +subsequent authentications. +For example, an +.Cm AuthenticationMethods +of +.Dq publickey,publickey +will require successful authentication using two different public keys. .Pp This option is only available for SSH protocol 2 and will yield a fatal error if enabled if protocol 1 is also enabled.