sshd_config
author terom@yzzrt-hyper.lan
Sun, 19 Oct 2008 22:33:43 +0300
changeset 0 e88b62deaec4
permissions -rw-r--r--
initial code
0
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     1
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     2
# what port to listen on 
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     3
Port 2828
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     4
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     5
# only allow members of the xmsh-users group and certain admins
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     6
AllowGroups xmsh-users
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     7
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     8
# use system hostkeys
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
     9
HostKey /etc/ssh/ssh_host_rsa_key
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    10
HostKey /etc/ssh/ssh_host_dsa_key
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    11
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    12
# runtime options
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    13
PidFile /home/xmsh/run/sshd.pid
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    14
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    15
# cosmetic options
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    16
Banner /home/xmsh/etc/banner
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    17
PrintLastLog yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    18
PrintMotd no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    19
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    20
# Logging
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    21
SyslogFacility AUTH
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    22
LogLevel INFO
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    23
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    24
# force some options
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    25
Protocol 2
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    26
UsePrivilegeSeparation yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    27
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    28
# Authentication:
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    29
LoginGraceTime 120
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    30
StrictModes yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    31
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    32
# behave like debian does
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    33
PasswordAuthentication yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    34
PubkeyAuthentication yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    35
ChallengeResponseAuthentication no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    36
UsePAM no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    37
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    38
# disable most features
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    39
AcceptEnv no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    40
AllowTcpForwarding no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    41
AuthorizedKeysFile no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    42
IgnoreRhosts yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    43
IgnoreUserKnownHosts yes
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    44
PermitRootLogin no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    45
PermitTunnel no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    46
PermitUserEnvironment no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    47
X11Forwarding no
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    48
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    49
# By default no subsystems are defined
e88b62deaec4 initial code
terom@yzzrt-hyper.lan
parents:
diff changeset
    50