Updated sshd config

This commit is contained in:
Héctor Molinero Fernández
2019-10-13 13:13:58 +02:00
parent e75903fce6
commit 92da9e1612
2 changed files with 29 additions and 29 deletions

View File

@@ -1,29 +1,26 @@
Protocol 2 Protocol 2
HostKey /etc/ssh/ssh_host_ed25519_key HostKey /etc/ssh/ssh_host_ed25519_key
HostKey /etc/ssh/ssh_host_rsa_key HostKey /etc/ssh/ssh_host_rsa_key
ListenAddress 0.0.0.0
Port 3322 Port 3322
ListenAddress 0.0.0.0 UseDNS no
UsePAM yes
StrictModes yes X11Forwarding yes
X11UseLocalhost no
UsePAM yes X11DisplayOffset 10
PermitRootLogin no AllowTcpForwarding yes
PubkeyAuthentication yes PermitRootLogin no
PasswordAuthentication yes PermitEmptyPasswords no
PermitEmptyPasswords no PermitUserEnvironment no
PubkeyAuthentication yes
PasswordAuthentication yes
ChallengeResponseAuthentication no ChallengeResponseAuthentication no
TCPKeepAlive yes GSSAPIAuthentication no
LoginGraceTime 30 LoginGraceTime 30
ClientAliveInterval 300 TCPKeepAlive yes
ClientAliveCountMax 1 ClientAliveInterval 60
ClientAliveCountMax 5
X11Forwarding yes PrintMotd no
X11DisplayOffset 10 PrintLastLog no
X11UseLocalhost no SyslogFacility AUTH
LogLevel INFO
PrintMotd no
PrintLastLog yes
SyslogFacility AUTH
LogLevel INFO

View File

@@ -45,8 +45,11 @@ if [ ! -f "${RANDFILE:?}" ]; then
fi fi
# Generate SSH keys if they do not exist # Generate SSH keys if they do not exist
if [ ! -f /etc/ssh/ssh_host_ed25519_key ]; then
ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key -N '' >/dev/null
fi
if [ ! -f /etc/ssh/ssh_host_rsa_key ]; then if [ ! -f /etc/ssh/ssh_host_rsa_key ]; then
DEBIAN_FRONTEND=noninteractive dpkg-reconfigure openssh-server ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key -N '' >/dev/null
fi fi
# Generate self-signed certificate # Generate self-signed certificate