From 49eea7a3eb1788c76a60d62439eb9df0ddc9f688 Mon Sep 17 00:00:00 2001 From: Ostantia <113256480+Ostantia@users.noreply.github.com> Date: Mon, 10 Apr 2023 10:30:09 +0200 Subject: [PATCH] =?UTF-8?q?Ajout=20du=20support=20pour=20d=C3=A9finition?= =?UTF-8?q?=20du=20port=20d'=C3=A9coute=20et=20formattage=20de=20sshd=5Fco?= =?UTF-8?q?nfig?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- sshd_config | 73 +++++++++++++++++++++++++++++++++++++++++++---------- 1 file changed, 60 insertions(+), 13 deletions(-) diff --git a/sshd_config b/sshd_config index 84395fc..4685c5c 100644 --- a/sshd_config +++ b/sshd_config @@ -12,28 +12,28 @@ Include /etc/ssh/sshd_config.d/*.conf -Port 22 +#Port 22 #AddressFamily any #ListenAddress 0.0.0.0 #ListenAddress :: -HostKey /etc/ssh/ssh_host_ed25519_key -HostKey /etc/ssh/ssh_host_ecdsa_key -HostKey /etc/ssh/ssh_host_rsa_key +#HostKey /etc/ssh/ssh_host_rsa_key +#HostKey /etc/ssh/ssh_host_ecdsa_key +#HostKey /etc/ssh/ssh_host_ed25519_key # Ciphers and keying #RekeyLimit default none # Logging #SyslogFacility AUTH -LogLevel VERBOSE +#LogLevel INFO # Authentication: #LoginGraceTime 2m -PermitRootLogin no +#PermitRootLogin prohibit-password #StrictModes yes -MaxAuthTries 6 +#MaxAuthTries 6 #MaxSessions 10 #PubkeyAuthentication yes @@ -55,7 +55,7 @@ MaxAuthTries 6 #IgnoreRhosts yes # To disable tunneled clear text passwords, change to no here! -PasswordAuthentication yes +#PasswordAuthentication yes #PermitEmptyPasswords no # Change to yes to enable challenge-response passwords (beware issues with @@ -85,13 +85,13 @@ ChallengeResponseAuthentication no # and ChallengeResponseAuthentication to 'no'. UsePAM yes -AllowAgentForwarding no +#AllowAgentForwarding yes #AllowTcpForwarding yes #GatewayPorts no -X11Forwarding no +#X11Forwarding yes #X11DisplayOffset 10 #X11UseLocalhost yes -PermitTTY yes +#PermitTTY yes PrintMotd no #PrintLastLog yes #TCPKeepAlive yes @@ -107,20 +107,67 @@ PrintMotd no #VersionAddendum none # no default banner path -Banner /root/scripts/monosphere_banner.txt +#Banner none # Allow client to pass locale environment variables AcceptEnv LANG LC_* # override default of no subsystems -Subsystem sftp /usr/lib/ssh/sftp-server -f AUTHPRIV -l INFO +#Subsystem sftp /usr/lib/openssh/sftp-server + +# Example of overriding settings on a per-user basis +#Match User anoncvs +# X11Forwarding no +# AllowTcpForwarding no +# PermitTTY no +# ForceCommand cvs server + #---Bastion configurations ! CHANGE AT YOUR OWN RISK !--- + +#Order by preference +HostKey /etc/ssh/ssh_host_ed25519_key +HostKey /etc/ssh/ssh_host_ecdsa_key +HostKey /etc/ssh/ssh_host_rsa_key + +#Logging +LogLevel VERBOSE + +#Authentication settings +PermitRootLogin no +MaxAuthTries 6 +PubkeyAuthentication yes +PasswordAuthentication yes +PermitEmptyPasswords no + +#Forwaring settings +AllowAgentForwarding no +PermitTTY yes +PrintMotd no +X11Forwarding no + +#Banner add +Banner /root/scripts/monosphere_banner.txt + +#Override subsystem defaults +Subsystem sftp /usr/lib/ssh/sftp-server -f AUTHPRIV -l INFO + +#Kex accepted protocols KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256 + +#Accepted ciphers Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr + +#Accepted MACs MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com + +#Accepted public key types PubkeyAcceptedKeyTypes sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com + +#Per user basis settings AllowStreamLocalForwarding no Match User *,!ubuntu ForceCommand /opt/public/scripts/server_menu.sh X11Forwarding no + +#Used port number