# HG changeset patch # User Matt Johnston # Date 1614694814 -28800 # Node ID ed20d805b33214e48907c32658ede7bb4cd6ff96 # Parent f90e681b8b8c9dc4692ee7e3cc847c92191c1f97 Disable UNAUTH_CLOSE_DELAY by default diff -r f90e681b8b8c -r ed20d805b332 default_options.h --- a/default_options.h Fri Jan 29 21:59:12 2021 +0800 +++ b/default_options.h Tue Mar 02 22:20:14 2021 +0800 @@ -256,8 +256,11 @@ /* -T server option overrides */ #define MAX_AUTH_TRIES 10 -/* Delay introduced before closing an unauthenticated session (seconds) */ -#define UNAUTH_CLOSE_DELAY 30 +/* Delay introduced before closing an unauthenticated session (seconds). + Disabled by default, can be set to say 30 seconds to reduce the speed + of password brute forcing. Note that there is a risk of denial of + service by setting this */ +#define UNAUTH_CLOSE_DELAY 0 /* The default file to store the daemon's process ID, for shutdown scripts etc. This can be overridden with the -P flag */