sshd_config 1.0 KB

1234567891011121314151617181920212223242526272829303132333435
  1. LogLevel INFO
  2. #LogLevel DEBUG
  3. PidFile none
  4. Port 2200
  5. Protocol 2
  6. HostKey /etc/ssh/host_keys/rsa
  7. HostKey /etc/ssh/host_keys/ed25519
  8. # https://www.ssh-audit.com/hardening_guides.html#ubuntu_20_04_lts
  9. KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha256
  10. Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
  11. MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128-etm@openssh.com
  12. HostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com
  13. UsePAM no
  14. PermitRootLogin no
  15. AllowUsers git
  16. PubkeyAuthentication yes
  17. PasswordAuthentication no
  18. ChallengeResponseAuthentication no
  19. StrictModes no
  20. DisableForwarding yes
  21. AllowAgentForwarding no
  22. AllowStreamLocalForwarding no
  23. AllowTcpForwarding no
  24. GatewayPorts no
  25. PermitTunnel no
  26. X11Forwarding no
  27. PermitUserEnvironment no
  28. PrintMotd no
  29. PermitTTY no