sshd.conf(5)
MILESTONE-QUALIFIED
Rendered from the page's mdoc source at milestone/general-usability-qemu-20260927 (platform ff025b1)
with GNU groff version 1.23.0, using the same command the image build uses; an ABSD session running
man 5 sshd.conf prints this text. It is dated 2026-09-27; the build commands and
repository files it mentions are in private sources, and later work is not in it.
All pages.
SSHD.CONF(5) File Formats Manual SSHD.CONF(5) NAME sshd.conf -- limits of the SSH server SYNOPSIS /etc/sshd.conf DESCRIPTION sshd reads sshd.conf once, when it starts, through the file server; changing the file takes effect at the next boot. It is not OpenSSH's sshd_config: the keywords differ and there are only these. Each line is a keyword and one value, separated by spaces or tabs. Blank lines and lines whose first word begins with `#' are ignored. Each keyword may appear once; values are decimal whole numbers. An absent keyword keeps its default. port number The TCP port to listen on, 1 to 65535. Default 22. max-connections number Connections served at once, authenticated or not, 1 to 8. Default 4. Each connection has one session. login-grace-time seconds How long a connection may take to authenticate before it is dropped, 1 to 3600. Default 30. idle-timeout seconds How long a connection may pass with no traffic in either direction and no output from its command before it is closed, 1 to 604800. Default 1800. max-auth-tries number Refused authentication attempts before the connection is dropped, 1 to 100. Default 6. Without the file every value is its default, and sshd says so on the console. The operator image installs the file with the default values. When every connection is taken While max-connections connections are open, sshd takes no new one. The next client's TCP connection is still completed by the network stack, up to max-connections more, but the client receives no SSH banner: it waits, and is served as soon as an open connection ends. Stock ssh gives up after its ConnectTimeout with "Connection timed out during banner exchange". Unauthenticated connections count: anyone who can reach the port can hold every connection for the login grace time, again and again. There is no limit per source address. Separately, every session needs a file server channel; there are ten. With at most 8 connections all ten are taken only when commands that earlier sessions left running still hold channels (see absd-sh(1)). A session that then finds none free is refused: a shell request fails, and stock ssh prints "shell request failed on channel 0" and exits with status 255; a command is not started, and the client gets "sshd: NAME: no free file server slot" and status 126. The channels come back as those commands end. DIAGNOSTICS At every start sshd prints on the console, and writes to /var/log/sshd: sshd: port 22, at most 4 connections, login grace 30 s, idle timeout 1800 s, 6 authentication tries (/etc/sshd.conf) A malformed file (an unknown keyword, including OpenSSH's such as Port, a keyword twice, a missing or extra value, a value out of range, a byte that is not printable ASCII, more than 4096 bytes) is refused: the console names the file, the line, and the reason, sshd does not start, and the boot fails. No default replaces a value the operator wrote. See afterboot(8) for fixing it. SEE ALSO network.conf(5), afterboot(8) ABSD September 27, 2026 SSHD.CONF(5)