rsh [-n] [-d] [-l login] host [command]
rsh [-n] [-d] -S secargs [-K certdir] [-k nickname] [-l login] host [command]
The -n flag indicates that rsh should not process any input.
The -d flag turns on some debugging.
The -S flag sets the security parameters. The secargs string should be two character long. If the first character is 'e' then encryption is enabled. Any other value of the first character will turn off encryption. If the second character is 'p' then a socks proxy is used. Any other value of the second character will disable socks and attempt to use a direct connection. NOTE: If you are using socks then you should have the environment variable SOCKS_HOST set to the name of your socks proxy machine.
The -K flag specifies the location of the key and certificate databases as the certdir directory. Without this flag, the default is /usr/etc/ssl, unless the environment variable SSL_DIR has been set to override this default.
The -k flag enables client authentication. If the server requests client authentication, the nickname string will be used to access the client's key and certificate. The user will then be prompted for a password for the key. The key and certificate databases will be read from the default directory, unless otherwise specified (see above).
The -l flag logs you into the remote host as login rather than the current local username.
host is the hostname or address of the machine to connect to and execute command.
If encryption is enabled then rsh will attempt to connect to the port for a service named "shells". If encryption is not being used then it will connect to the standard "shell" port. If you want to use encryption then you should add a line to /etc/services specifying a port for the "shells" service.
If you don't enable encryption or socks use via -S then this rsh acts like the normal bsd version of rsh.
rsh needs to be suid root, or be run as root.
WARNING: This version of rshd has its reserved port checking disabled. This enables use of secure rsh through a socks proxy, but it bypasses one of the traditional security measures of unix based networking. This is probably not much of a loss given how easy it is to get around today, but it may introduce a security hole if things are not configured correctly. It is strongly recomended that you configure ssld to use an access control list to ensure that only trusted people can access your system via rshd.
A sample line from the ssld configuration file to enable rshd might look like this:
#Port Mode ACL Key Cert Action 445 auth-server rsh.acl NAME NAME exec ./rshd rshdNotice that this configuration requires client authentication and has an access control list. Both are highly recommended.
The default pathname for secure rsh is /usr/etc/ssl/srsh. You can override this with the -P option in rdist.
The version of rdistd included here has not been modified. It is included here for completeness. If you already have the current version of rdistd installed on the target system then you do not need to install this version.
WARNING: Since this version of rdist uses secure rsh, the same security considerations mentioned for rsh and rshd apply to rdist.