sshd_config 960 B

123456789101112131415161718192021222324252627282930
  1. LogLevel INFO
  2. #LogLevel DEBUG
  3. PidFile none
  4. Port 2200
  5. Protocol 2
  6. HostKey /etc/ssh/host_keys/rsa
  7. HostKey /etc/ssh/host_keys/ed25519
  8. # https://www.ssh-audit.com/hardening_guides.html#ubuntu_20_04_lts
  9. KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group-exchange-sha256
  10. Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
  11. MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128-etm@openssh.com
  12. HostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com
  13. UsePAM no
  14. PermitRootLogin no
  15. PasswordAuthentication no
  16. ChallengeResponseAuthentication no
  17. StrictModes no
  18. AllowAgentForwarding no
  19. AllowTcpForwarding no
  20. GatewayPorts no
  21. X11Forwarding no
  22. PermitUserEnvironment no
  23. PrintMotd no
  24. PermitTTY no