From fdee8798a37281f1fd4a645505062d06d7d8c026 Mon Sep 17 00:00:00 2001 From: Chris Koeritz Date: Tue, 2 Jun 2020 09:52:57 -0400 Subject: [PATCH] added note for tighter sshd config --- .../ssh/mods_for_etc_sshd_config.txt | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 infobase/configuration/ssh/mods_for_etc_sshd_config.txt diff --git a/infobase/configuration/ssh/mods_for_etc_sshd_config.txt b/infobase/configuration/ssh/mods_for_etc_sshd_config.txt new file mode 100644 index 00000000..322fdbac --- /dev/null +++ b/infobase/configuration/ssh/mods_for_etc_sshd_config.txt @@ -0,0 +1,17 @@ + +to increase security on an sshd server, and assuming you have +registered your ssh keys ahead of time in authorized_keys, then +this bit goes in /etc/sshd_config (at the end works fine): + +############## + +# fred mods 2019-02-19: +# trying to keep intruders out... this disables password logins. +# also of course disables root logins, which should already have been done. +PermitRootLogin no +ChallengeResponseAuthentication no +PasswordAuthentication no +UsePAM no + +############## + -- 2.34.1