.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
-.\" $OpenBSD: ssh_config.5,v 1.368 2022/02/04 02:49:17 dtucker Exp $
-.Dd $Mdocdate: February 4 2022 $
+.\" $OpenBSD: ssh_config.5,v 1.369 2022/02/15 05:13:36 djm Exp $
+.Dd $Mdocdate: February 15 2022 $
.Dt SSH_CONFIG 5
.Os
.Sh NAME
Specifies whether to try public key authentication.
The argument to this keyword must be
.Cm yes
-(the default)
+(the default),
+.Cm no ,
+.Cm unbound
or
-.Cm no .
+.Cm host-bound .
+The final two options enable public key authentication while respectively
+disabling or enabling the OpenSSH host-bound authentication protocol
+extension required for restricted
+.Xr ssh-agent 1
+forwarding.
.It Cm RekeyLimit
Specifies the maximum amount of data that may be transmitted before the
session key is renegotiated, optionally followed by a maximum amount of