瀏覽代碼

defaults: enable secure defaults on sshd_config

tags/v0.41.0
ek9 8 年之前
父節點
當前提交
f5a74f3fa0
共有 1 個檔案被更改,包括 20 行新增0 行删除
  1. +20
    -0
      openssh/defaults.yaml

+ 20
- 0
openssh/defaults.yaml 查看文件

@@ -10,6 +10,26 @@ openssh:
dig_pkg: dnsutils
ssh_moduli: /etc/ssh/moduli
root_group: root
KexAlgorithms:
- 'curve25519-sha256@libssh.org'
- 'diffie-hellman-group-exchange-sha256'
Ciphers:
- 'chacha20-poly1305@openssh.com'
- 'aes256-gcm@openssh.com'
- 'aes128-gcm@openssh.com'
- 'aes256-ctr'
- 'aes192-ctr'
- 'aes128-ctr'
MACs:
- 'hmac-sha2-512-etm@openssh.com'
- 'hmac-sha2-256-etm@openssh.com'
- 'hmac-ripemd160-etm@openssh.com'
- 'umac-128-etm@openssh.com'
- 'hmac-sha2-512'
- 'hmac-sha2-256'
- 'hmac-ripemd160'
- 'umac-128@openssh.com'

sshd_config: {}
ssh_config:
Hosts:

Loading…
取消
儲存