SSH_CONFIG(5) File Formats Manual SSH_CONFIG(5) (NAME) ssh_config - OpenSSH (DESCRIPTION) ssh(1) : 1. 2. (~/.ssh/config) 3. (/etc/ssh/ssh_config) . Host Match . . . / . `#' () . `#' . . (") . `=' ( ) -o ssh, scp sftp . ( ): Host ( Host Match) . . `*' . hostname ( CanonicalizeHostname ). (`!') . Host . (wildcard) . (PATTERNS) . Match ( Host Match) Match . all . : canonical, final, exec, localnetwork, host, originalhost, tagged, command, user, localuser version. all canonical final . . all, canonical final . (`!') . canonical (canonicalization) ( CanonicalizeHostname ). . final ( CanonicalizeHostname ) . CanonicalizeHostname canonical final . exec . . . exec (TOKENS) . localnetwork CIDR . . ( DHCP ) . (PATTERNS) . host Hostname CanonicalizeHostname . originalhost . tagged Tag ssh(1) -P . command ( "sftp" SFTP) . `Match tag ""'. version ssh(1) "OpenSSH_10.0". user . localuser ssh(1) ( ssh_config ). sessiontype shell exec subsystem sftp(1) none ssh(1) -N . Include ( ) . glob(7) (TOKENS) (ENVIRONMENT VARIABLES) `~' . . ~/.ssh /etc/ssh . Include Match Host . AddKeysToAgent ssh-agent(1) . yes ssh-add(1) . ask ssh(1) SSH_ASKPASS ( ssh-add(1) ). confirm -c ssh-add(1) . no . (TIME FORMATS) sshd_config(5) ssh-agent(1) . no () yes confirm ( ) ask . AddressFamily . any () inet ( IPv4) inet6 ( IPv6). BatchMode yes . (batch) ssh(1) . yes no () . BindAddress . . BindInterface . CanonicalDomains CanonicalizeHostname . CanonicalizeFallbackLocal . yes (unqualified) (resolver) . no ssh(1) CanonicalizeHostname CanonicalDomains . CanonicalizeHostname . no . yes ProxyCommand ProxyJump ssh(1) CanonicalDomains CanonicalizePermittedCNAMEs . CanonicalizeHostname always . Host Match . none ProxyJump . CanonicalizeMaxDots . 1 ( hostname.subdomain). CanonicalizePermittedCNAMEs CNAME . source_domain_list:target_domain_list source_domain_list CNAME target_domain_list . "*.a.example.com:*.b.example.com,*.c.example.com" "*.a.example.com" "*.b.example.com" "*.c.example.com" . "none" CNAME . . CASignatureAlgorithms (CA) . : ssh-ed25519,ecdsa-sha2-nistp256, ecdsa-sha2-nistp384,ecdsa-sha2-nistp521, sk-ssh-ed25519@openssh.com, sk-ecdsa-sha2-nistp256@openssh.com, rsa-sha2-512,rsa-sha2-256, ssh-mldsa44-ed25519@openssh.com `+' . `-' ( ) . ssh(1) . CertificateFile . IdentityFile -i ssh(1) ssh-agent(1) PKCS11Provider SecurityKeyProvider. CertificateFile (TOKENS) (ENVIRONMENT VARIABLES) . . CertificateFile . ChannelTimeout ssh(1) . "type=interval" "type" "global" . "interval" (TIME FORMATS) . "session=5m" . . "global" . . . : agent-connection ssh-agent(1). direct-tcpip, direct-streamlocal@openssh.com TCP ( ) ssh(1) LocalForward DynamicForward. forwarded-tcpip, forwarded-streamlocal@openssh.com TCP ( ) sshd(8) ssh(1) RemoteForward. session scp(1) sftp(1) . tun-connection TunnelForward. x11-connection X11. X11 . SSH . . . CheckHostIP yes ssh(1) IP known_hosts . DNS (DNS spoofing) StrictHostKeyChecking ~/.ssh/known_hosts . no () . Ciphers . . `+' . `-' ( ) . `^' . : 3des-cbc aes128-cbc aes192-cbc aes256-cbc aes128-ctr aes192-ctr aes256-ctr aes128-gcm@openssh.com aes256-gcm@openssh.com chacha20-poly1305@openssh.com : chacha20-poly1305@openssh.com, aes128-gcm@openssh.com,aes256-gcm@openssh.com, aes128-ctr,aes192-ctr,aes256-ctr "ssh -Q cipher" . ClearAllForwardings . ssh(1) scp(1) sftp(1) . yes no () . Compression . yes no () . SSH . ( ) . . ConnectionAttempts ( ) . . . 1 . ConnectTimeout ( ) SSH TCP . SSH . ControlMaster (multiplexing). yes ssh(1) ControlPath . ControlPath ControlMaster no () . (master) . ask ssh(1) ssh-askpass(1) . ControlPath ssh(1) . X11 ssh-agent(1) . (opportunistic multiplexing) : . : auto autoask. ask . ControlPath ControlMaster none . ControlPath (TOKENS) (ENVIRONMENT VARIABLES) . ControlPath %h %p %r ( %C) . . ControlPersist ControlMaster ( ) . no () . yes 0 ( "ssh -O exit" ). sshd_config(5) ( ) . DynamicForward TCP . [bind_address:]port . IPv6 () . GatewayPorts (bind) . bind_address . bind_address localhost `*' . SOCKS4 SOCKS5 ssh(1) SOCKS . . ( ) (privileged) . EnableEscapeCommandline EscapeChar ( `~C'). . EnableSSHKeysign yes /etc/ssh/ssh_config ssh-keysign(8) HostbasedAuthentication . yes no () . . ssh-keysign(8) . EscapeChar (escape) (: `~'). . `^' none ( ) . ExitOnForwardFailure ssh(1) ( ) . ExitOnForwardFailure TCP ssh(1) . yes no () . FingerprintHash . : md5 sha256 (). ForkAfterAuthentication ssh . ssh . StdinNull "yes" . X11 ssh -f host xterm ForkAfterAuthentication "yes " ssh host xterm . ExitOnForwardFailure "yes" ForkAfterAuthentication "yes" . yes ( -f) no () . ForwardAgent ( ) . yes no () ( `$' ) . . ( ) . . ForwardX11 X11 DISPLAY . yes no () . X11 . ( X11 ) X11 . ForwardX11Trusted (keystroke monitoring) . ForwardX11Timeout X11 (TIME FORMATS) sshd_config(5) . X11 ssh(1) . ForwardX11Timeout X11 . X11 . ForwardX11Trusted yes X11 X11 . no () X11 X11 . xauth(1) . . X11 SECURITY . GatewayPorts . ssh(1) loopback . . GatewayPorts ssh (wildcard) . yes no () . GlobalKnownHostsFile . /etc/ssh/ssh_known_hosts, /etc/ssh/ssh_known_hosts2. GSSAPIAuthentication GSSAPI . no . GSSAPIDelegateCredentials () . no . HashKnownHosts ssh(1) ~/.ssh/known_hosts () . ssh(1) sshd(8) . no . ssh-keygen(1) . HostbasedAcceptedAlgorithms . `+' . `-' ( ) . `^' . : ssh-ed25519-cert-v01@openssh.com, ecdsa-sha2-nistp256-cert-v01@openssh.com, ecdsa-sha2-nistp384-cert-v01@openssh.com, ecdsa-sha2-nistp521-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, sk-ecdsa-sha2-nistp256-cert-v01@openssh.com, webauthn-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, ssh-mldsa44-ed25519-cert-v01@openssh.com, ssh-ed25519, ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521, sk-ssh-ed25519@openssh.com, sk-ecdsa-sha2-nistp256@openssh.com, webauthn-sk-ecdsa-sha2-nistp256@openssh.com, rsa-sha2-512,rsa-sha2-256, ssh-mldsa44-ed25519@openssh.com -Q ssh(1) . HostbasedKeyTypes . HostbasedAuthentication rhosts . yes no () . HostKeyAlgorithms . `+' . `-' ( ) . `^' . : ssh-ed25519-cert-v01@openssh.com, ecdsa-sha2-nistp256-cert-v01@openssh.com, ecdsa-sha2-nistp384-cert-v01@openssh.com, ecdsa-sha2-nistp521-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, sk-ecdsa-sha2-nistp256-cert-v01@openssh.com, webauthn-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, ssh-mldsa44-ed25519-cert-v01@openssh.com, ssh-ed25519, ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521, sk-ecdsa-sha2-nistp256@openssh.com, webauthn-sk-ecdsa-sha2-nistp256@openssh.com sk-ssh-ed25519@openssh.com, rsa-sha2-512,rsa-sha2-256, ssh-mldsa44-ed25519@openssh.com . "ssh -Q HostKeyAlgorithms" . HostKeyAlias . SSH . Hostname . . Hostname (TOKENS) . IP ( Hostname). . IdentitiesOnly ssh(1) ( ssh_config ssh(1) ) ssh-agent(1) PKCS11Provider SecurityKeyProvider . yes no () . ssh-agent . IdentityAgent UNIX . SSH_AUTH_SOCK . none . "SSH_AUTH_SOCK" SSH_AUTH_SOCK . `$' . IdentityAgent (TOKENS) (ENVIRONMENT VARIABLES) . IdentityFile ECDSA ECDSA Ed25519 Ed25519 RSA . ssh-agent(1) . ~/.ssh/id_rsa, ~/.ssh/id_ecdsa, ~/.ssh/id_ecdsa_sk, ~/.ssh/id_ed25519, ~/.ssh/id_ed25519_sk ~/.ssh/id_mldsa44_ed25519. IdentitiesOnly . CertificateFile ssh(1) -cert.pub IdentityFile . IdentityFile (TOKENS) . none . . IdentityFile ( ). IdentityFile IdentitiesOnly . IdentityFile CertificateFile . IgnoreUnknown . ssh_config ssh(1) . IgnoreUnknown . IPQoS Differentiated Services Field Codepoint (DSCP) . af11, af12, af13, af21, af22, af23, af31, af32, af33, af41, af42, af43, cs0, cs1, cs2, cs3, cs4, cs5, cs6, cs7, ef, le, none . . . . ef (Expedited Forwarding) none ( ) . KbdInteractiveAuthentication (keyboard-interactive) . yes () no . ChallengeResponseAuthentication . KbdInteractiveDevices . . . . OpenSSH bsdauth pam . KexAlgorithms KEX ( ) . . . `+' . `-' ( ) . `^' . : mlkem768x25519-sha256, sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com, curve25519-sha256,curve25519-sha256@libssh.org, ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521, diffie-hellman-group-exchange-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group14-sha256 "ssh -Q kex" . KnownHostsCommand UserKnownHostsFile GlobalKnownHostsFile . . ( (VERIFYING HOST KEYS) ssh(1)) . KnownHostsCommand (TOKENS) . : CheckHostIP . . LocalCommand . . LocalCommand (TOKENS) . (synchronous) ssh(1) . . PermitLocalCommand . LocalForward TCP ( ) . TCP [bind_address:]port . host:hostport . IPv6 . '/' ( ) TCP . . . GatewayPorts . bind_address . bind_address localhost `*' . (TOKENS) (ENVIRONMENT VARIABLES) . LogLevel ssh(1) . : QUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1, DEBUG2, DEBUG3. INFO . DEBUG DEBUG1 . DEBUG2 DEBUG3 . LogVerbose (override) LogLevel . . : kex.c:*:1000,*:kex_exchange_identification():*,packet.c:* kex.c kex_exchange_identification() packet.c . . MACs MAC ( ) . MAC . . `+' . `-' ( ) . `^' . "-etm" MAC (encrypt-then-mac). . : umac-64-etm@openssh.com,umac-128-etm@openssh.com, hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, umac-64@openssh.com,umac-128@openssh.com, hmac-sha2-256,hmac-sha2-512,hmac-sha1 MAC "ssh -Q mac" . NoHostAuthenticationForLocalhost localhost ( loopback) . yes no () . NumberOfPasswordPrompts . . 3 . ObscureKeystrokeTiming ssh(1) . ssh(1) . yes no interval:milliseconds ( interval:80 ) . . . PasswordAuthentication . yes () no . PermitLocalCommand LocalCommand !command ssh(1) . yes no () . PermitRemoteOpen TCP RemoteForward SOCKS . : PermitRemoteOpen host:port PermitRemoteOpen IPv4_addr:port PermitRemoteOpen [IPv6_addr]:port . any . none . `*' . . PKCS11Provider PKCS#11 none () . PKCS#11 ssh(1) PKCS#11 . Port . 22 . PreferredAuthentications . ( keyboard-interactive) ( password) . : gssapi-with-mic,hostbased,publickey, keyboard-interactive,password ProxyCommand . `exec' . ProxyCommand (TOKENS) . . sshd(8) sshd -i . Hostname ( ). none . CheckHostIP . nc(1) . HTTP 192.0.2.0 : ProxyCommand /usr/bin/nc -X connect -x 192.0.2.0:8080 %h %p ProxyJump (jump proxy) [user@]host[:port] URI . . ssh(1) ssh(1) ProxyJump TCP . none . ProxyCommand . ( ) . ~/.ssh/config . ProxyUseFdpass ProxyCommand ssh(1) . no . PubkeyAcceptedAlgorithms . `+' . `-' ( ) . `^' . : ssh-ed25519-cert-v01@openssh.com, ecdsa-sha2-nistp256-cert-v01@openssh.com, ecdsa-sha2-nistp384-cert-v01@openssh.com, ecdsa-sha2-nistp521-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, sk-ecdsa-sha2-nistp256-cert-v01@openssh.com, webauthn-sk-ecdsa-sha2-nistp256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, ssh-mldsa44-ed25519-cert-v01@openssh.com, ssh-ed25519, ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521, sk-ssh-ed25519@openssh.com, sk-ecdsa-sha2-nistp256@openssh.com, webauthn-sk-ecdsa-sha2-nistp256@openssh.com, rsa-sha2-512,rsa-sha2-256, ssh-mldsa44-ed25519@openssh.com "ssh -Q PubkeyAcceptedAlgorithms" . PubkeyAuthentication . yes () no unbound host-bound . (host-bound) OpenSSH ssh-agent(1) . RefuseConnection . ssh(1) . ssh_config . RekeyLimit . `K ' `M' `G' . `1G' `4G' . TIME FORMATS sshd_config(5) . RekeyLimit default none . RemoteCommand . . RemoteCommand (TOKENS) . RemoteForward TCP . SOCKS 4/5 . [bind_address:]port . host:hostport SOCKS . SOCKS PermitRemoteOpen . IPv6 . '/' ( ) TCP . . (root) . (TOKENS) (ENVIRONMENT VARIABLES) . port 0 . bind_address loopback . bind_address `*' . bind_address GatewayPorts ( sshd_config(5) ). RequestTTY (pseudo-tty) . : no ( TTY ) yes ( TTY ) force ( TTY ) auto ( ). -t -T ssh(1) . RequiredRSASize RSA ( ) ssh(1) . . . 1024 . . RevokedHostKeys . . . (KRL) OpenSSH ssh-keygen(1) . KRL KEY REVOCATION LISTS ssh-keygen(1) . RevokedHostKeys (TOKENS) (ENVIRONMENT VARIABLES) . SecurityKeyProvider FIDO USB HID . `$' . SendEnv environ(7) . . TERM . AcceptEnv sshd_config(5) . . SendEnv . (PATTERNS) . SendEnv - . . ServerAliveCountMax (server alive messages - ) ssh(1) . ssh . TCPKeepAlive ( ) . . TCP keepalive TCPKeepAlive . . 3 . ServerAliveInterval ( ) ServerAliveCountMax ssh . ServerAliveInterval ssh(1) . 0 . SessionType . . none ( -N) - subsystem ( -s) default ( ) . SetEnv "NAME=VALUE" . SendEnv TERM . "VALUE" (TOKENS) (ENVIRONMENT VARIABLES) . StdinNull (stdin) /dev/null ( stdin ). ssh -n . yes ( -n) no () . StreamLocalBindMask (umask) . . 0177 . . StreamLocalBindUnlink . StreamLocalBindUnlink ssh . . yes no () . StrictHostKeyChecking yes ssh(1) ~/.ssh/known_hosts . (MITM) /etc/ssh/ssh_known_hosts . . accept-new ssh known_hosts . no off ssh . ask () ssh . . SyslogFacility (facility code) ssh(1) . : DAEMON, USER, AUTH, LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7. USER . TCPKeepAlive keepalive TCP . . . yes ( TCP keepalive) . . TCP keepalive no . ServerAliveInterval . Tag Match . Tunnel tun(4) . yes point-to-point ( ) ethernet ( ) no () . yes point-to-point . TunnelDevice tun(4) (local_tun) (remote_tun) . local_tun[:remote_tun] . any . remote_tun any . any:any . UpdateHostKeys ssh(1) UserKnownHostsFile . yes no ask . (key rotation) . UserKnownHostsFile ( GlobalKnownHostsFile) . UpdateHostKeys UserKnownHostsFile VerifyHostKeyDNS UpdateHostKeys no . UpdateHostKeys ask known_hosts . ControlPersist . sshd(8) OpenSSH 6.8 "hostkeys@openssh.com" . User . . . User (TOKENS) ( %r %C) (ENVIRONMENT VARIABLES) . UserKnownHostsFile . (TOKENS) (ENVIRONMENT VARIABLES) . none ssh(1) . ~/.ssh/known_hosts, ~/.ssh/known_hosts2. VerifyHostKeyDNS DNS SSHFP . yes DNS . ask . ask StrictHostKeyChecking . no . (VERIFYING HOST KEYS) ssh(1) . VersionAddendum SSH . none . VisualHostKey yes (ASCII art) . no () . WarnWeakCrypto . . no-pq-kex . no . yes . XAuthLocation xauth(1) . /usr/bin/xauth . (PATTERNS) `*' ( ) `?' ( ) . ".co.uk " : Host *.co.uk 192.168.0.[0-9] : Host 192.168.0.? - . (`!') . "dialup " ( authorized_keys) : from="!*.dialup.example.com,*.example.com" . "host3" : from="!host1,!host2" : from="!host1,!host2,*" (TOKENS) () . . . ssh_config : %% `%'. %C () %l%h%p%r%j. %d . %f . %H known_hosts . %h . %I KnownHostsCommand : ADDRESS ( CheckHostIP ) HOSTNAME ORDER . %i (UID). %j ProxyJump . %K base64. %k . %L . %l . %n . %p . %r . %T tun(4) tap(4) "NONE" . %t ssh-ed25519. %u . CertificateFile, ControlPath, IdentityAgent, IdentityFile, Include, KnownHostsCommand, LocalForward, Match exec, RemoteCommand, RemoteForward, RevokedHostKeys, UserKnownHostsFile VersionAddendum %%, %C, %d, %h, %i, %j, %k, %L, %l, %n, %p, %r %u . KnownHostsCommand %f, %H, %I, %K %t . Hostname %% %h . LocalCommand . ProxyCommand ProxyJump %%, %h, %n, %p %r . . ssh(1) ( ) ssh(1) . (ENVIRONMENT VARIABLES) ${} ${HOME}/.ssh .ssh . . CertificateFile, ControlPath, IdentityAgent, IdentityFile, Include, KnownHostsCommand UserKnownHostsFile . LocalForward RemoteForward . (FILES) ~/.ssh/config . . SSH . : / . /etc/ssh/ssh_config . . . (SEE ALSO) ssh(1) (AUTHORS) OpenSSH ssh 1.2.12 Tatu Ylonen . Aaron Campbell, Bob Beck, Markus Friedl, Niels Provos, Theo de Raadt Dug Song OpenSSH . Markus Friedl 1.5 2.0 SSH . Linux 6.12.107+deb13-amd64 July 11, 2026 Linux 6.12.107+deb13-amd64