aboutsummaryrefslogtreecommitdiff
path: root/sshd_config
blob: f183761416c46bdb8881189ddfc724d607fed330 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
KexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp521,ecdh-sha2-nistp384,ecdh-sha2-nistp256,diffie-hellman-group-exchange-sha256
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,umac-128@openssh.com

StrictModes yes
PermitRootLogin no
LoginGraceTime 30
MaxAuthTries 3
MaxSessions 5
MaxStartups 2

AuthorizedKeysFile .ssh/authorized_keys
HostbasedAuthentication no
IgnoreRhosts yes
PermitEmptyPasswords no
ChallengeResponseAuthentication no
Compression yes
PrintMotd no
UsePAM yes

Subsystem sftp internal-sftp
AllowTcpForwarding no
PermitTunnel no
PermitTTY no
X11Forwarding no

AllowUsers $NEW_USER
Match User $NEW_USER # Note: Indentation below is just stylistic
  AllowTcpForwarding yes
  PermitTunnel yes
  PermitTTY yes
  X11Forwarding yes
  X11UseLocalhost no