From ff1463ba59260c3df518755d978b4e18272bf454 Mon Sep 17 00:00:00 2001 From: Alexis Hovorka Date: Mon, 4 Jan 2021 00:06:27 -0700 Subject: Initial commit --- sshd_config | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 sshd_config (limited to 'sshd_config') diff --git a/sshd_config b/sshd_config new file mode 100644 index 0000000..f183761 --- /dev/null +++ b/sshd_config @@ -0,0 +1,33 @@ +KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256 +Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr +MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com + +StrictModes yes +PermitRootLogin no +LoginGraceTime 30 +MaxAuthTries 3 +MaxSessions 5 +MaxStartups 2 + +AuthorizedKeysFile .ssh/authorized_keys +HostbasedAuthentication no +IgnoreRhosts yes +PermitEmptyPasswords no +ChallengeResponseAuthentication no +Compression yes +PrintMotd no +UsePAM yes + +Subsystem sftp internal-sftp +AllowTcpForwarding no +PermitTunnel no +PermitTTY no +X11Forwarding no + +AllowUsers $NEW_USER +Match User $NEW_USER # Note: Indentation below is just stylistic + AllowTcpForwarding yes + PermitTunnel yes + PermitTTY yes + X11Forwarding yes + X11UseLocalhost no -- cgit v1.2.3-70-g09d2