From bc602b83cbb3ff6d47216935865843391c5c6f6c Mon Sep 17 00:00:00 2001 From: Siphonight Date: Thu, 24 Jul 2025 15:20:25 +0200 Subject: [PATCH] =?UTF-8?q?Amelioration=20s=C3=A9curit=C3=A9=20de=20la=20c?= =?UTF-8?q?onfiguration=20SSHD?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Amélioration de la configuration de la sécurité du daemon SSHD du bastion à l'aide de l'outil ssh-audit. (Disponible ici : https://github.com/jtesta/ssh-audit) --- sshd_config | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/sshd_config b/sshd_config index 0ce3926..b4840f9 100644 --- a/sshd_config +++ b/sshd_config @@ -126,15 +126,18 @@ AcceptEnv LANG LC_* #Order by preference HostKey /etc/ssh/ssh_host_ed25519_key -HostKey /etc/ssh/ssh_host_ecdsa_key HostKey /etc/ssh/ssh_host_rsa_key #Logging +SyslogFacility AUTH LogLevel VERBOSE #Authentication settings PermitRootLogin no MaxAuthTries 6 +MaxSessions 6 +MaxStartups 4:50:8 +PerSourceMaxStartups 2 PermitEmptyPasswords no #Forwaring settings @@ -150,16 +153,13 @@ Banner /root/scripts/monosphere_banner.txt Subsystem sftp /usr/lib/ssh/sftp-server -f AUTHPRIV -l INFO #Kex accepted protocols -KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256 +kexalgorithms sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512 #Accepted ciphers Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr #Accepted MACs -MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com - -#Accepted public key types -#PubkeyAcceptedKeyTypes sk-ecdsa-sha2-nistp256-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,sk-ecdsa-sha2-nistp256@openssh.com +MACs umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com #Per user basis settings AllowStreamLocalForwarding no