X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fssh%2Ftemplates%2Fsshd_config.erb;h=7a8ff877cbc900b5cd7c0f861fd7838a742bff41;hb=6f2e5fc86e49c12b12eef39fc69e0e810a32c318;hp=cb22f092caa4065bc987359dec5c87808b0090ed;hpb=847817bf26fd25044c20519516f2b3f8de1a61b6;p=mirror%2Fdsa-puppet.git diff --git a/modules/ssh/templates/sshd_config.erb b/modules/ssh/templates/sshd_config.erb index cb22f092c..7a8ff877c 100644 --- a/modules/ssh/templates/sshd_config.erb +++ b/modules/ssh/templates/sshd_config.erb @@ -8,11 +8,13 @@ # What ports, IPs and protocols we listen for Port 22 -<%= extraports = case fqdn - when "ravel.debian.org" then "Port 443" +<%= extraports = case @fqdn when "paradis.debian.org" then " -Port 5.153.231.31:443 -Port 2001:41c8:1000:21::21:31:443" +ListenAddress 0.0.0.0:22 +ListenAddress [::]:22 +ListenAddress 5.153.231.31:443 +ListenAddress [2001:41c8:1000:21::21:31]:443 +" end extraports %> @@ -22,12 +24,15 @@ extraports Protocol 2 # HostKeys for protocol version 2 HostKey /etc/ssh/ssh_host_rsa_key +<%- if has_variable?("has_etc_ssh_ssh_host_ed25519_key") && @has_etc_ssh_ssh_host_ed25519_key == "true" -%> +HostKey /etc/ssh/ssh_host_ed25519_key +<% end %> #Privilege Separation is turned on for security UsePrivilegeSeparation yes # Lifetime and size of ephemeral version 1 server key KeyRegenerationInterval 3600 -ServerKeyBits 768 +ServerKeyBits 1024 # Logging SyslogFacility AUTH @@ -83,10 +88,7 @@ AcceptEnv LANG LC_* Subsystem sftp /usr/lib/openssh/sftp-server UsePAM yes -<% if %w{squeeze}.include?(scope.lookupvar('::lsbdistcodename')) %> -AuthorizedKeysFile /etc/ssh/userkeys/%u -AuthorizedKeysFile2 /var/lib/misc/userkeys/%u -<% else %> + AuthorizedKeysFile /etc/ssh/userkeys/%u /var/lib/misc/userkeys/%u /etc/ssh/userkeys/%u.more -<% end %> + PasswordAuthentication no