123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172 |
- # What ports, IPs and protocols we listen for
- Port 22
- # Use these options to restrict which interfaces/protocols sshd will bind to
- #ListenAddress ::
- #ListenAddress 0.0.0.0
-
- Protocol 2
-
- # HostKeys for protocol version 2
- HostKey /etc/ssh/ssh_host_rsa_key
- #Privilege Separation is turned on for security
- UsePrivilegeSeparation yes
-
- KexAlgorithms {{ kex_algorithms }}
- Ciphers {{ ciphers }}
- MACs {{ macs }}
-
- # Lifetime and size of ephemeral version 1 server key
- KeyRegenerationInterval 3600
- ServerKeyBits 768
-
- # Logging
- SyslogFacility AUTH
- LogLevel INFO
-
- # Authentication:
- LoginGraceTime 120
- PermitRootLogin no
- StrictModes yes
-
- RSAAuthentication yes
- PubkeyAuthentication yes
-
- # Don't read the user's ~/.rhosts and ~/.shosts files
- IgnoreRhosts yes
- # For this to work you will also need host keys in /etc/ssh_known_hosts
- RhostsRSAAuthentication no
- # similar for protocol version 2
- HostbasedAuthentication no
-
- PermitEmptyPasswords no
-
- # Change to yes to enable challenge-response passwords (beware issues with
- # some PAM modules and threads)
- ChallengeResponseAuthentication yes
-
- # Change to no to disable tunnelled clear text passwords
- PasswordAuthentication no
-
-
- X11Forwarding yes
- X11DisplayOffset 10
- PrintMotd no
- PrintLastLog yes
- TCPKeepAlive yes
-
- # Allow client to pass locale environment variables
- AcceptEnv LANG LC_*
-
- Subsystem sftp /usr/lib/openssh/sftp-server
-
- # Set this to 'yes' to enable PAM authentication, account processing,
- # and session processing. If this is enabled, PAM authentication will
- # be allowed through the ChallengeResponseAuthentication and
- # PasswordAuthentication. Depending on your PAM configuration,
- # PAM authentication via ChallengeResponseAuthentication may bypass
- # the setting of "PermitRootLogin without-password".
- # If you just want the PAM account and session checks to run without
- # PAM authentication, then enable this but set PasswordAuthentication
- # and ChallengeResponseAuthentication to 'no'.
- UsePAM yes
|