X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=modules%2Fssh%2Ftemplates%2Fsshd_config.erb;h=947a254755d1f5918ab61c58a1e4ce9ef9c8099e;hb=c3515fa2502698f50967878d0f5513f338891a8b;hp=840a7f87cd99de05ec02949fdb77d87873bb0d40;hpb=0d5176e1034bd04ce9c76d790caa819f8b8d5341;p=mirror%2Fdsa-puppet.git diff --git a/modules/ssh/templates/sshd_config.erb b/modules/ssh/templates/sshd_config.erb index 840a7f87c..947a25475 100644 --- a/modules/ssh/templates/sshd_config.erb +++ b/modules/ssh/templates/sshd_config.erb @@ -1,12 +1,20 @@ +## +## THIS FILE IS UNDER PUPPET CONTROL. DON'T EDIT IT HERE. +## USE: git clone git+ssh://$USER@puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet.git +## + # Package generated configuration file # See the sshd(8) manpage for details # What ports, IPs and protocols we listen for Port 22 -<%- extraports = case fqdn - when "ravel.debian.org" then "Port 443" - when "gluck.debian.org" then "Port 443" - when "agnesi.debian.org" then "Port 2260" +<%= extraports = case fqdn + when "paradis.debian.org" then " +ListenAddress 0.0.0.0:22 +ListenAddress [::]:22 +ListenAddress 5.153.231.31:443 +ListenAddress [2001:41c8:1000:21::21:31]:443 +" end extraports %> @@ -16,12 +24,15 @@ extraports Protocol 2 # HostKeys for protocol version 2 HostKey /etc/ssh/ssh_host_rsa_key +<%- if has_variable?("has_etc_ssh_ssh_host_ed25519_key") && has_etc_ssh_ssh_host_ed25519_key == "true" -%> +HostKey /etc/ssh/ssh_host_ed25519_key +<% end %> #Privilege Separation is turned on for security UsePrivilegeSeparation yes # Lifetime and size of ephemeral version 1 server key KeyRegenerationInterval 3600 -ServerKeyBits 768 +ServerKeyBits 1024 # Logging SyslogFacility AUTH @@ -77,6 +88,10 @@ AcceptEnv LANG LC_* Subsystem sftp /usr/lib/openssh/sftp-server UsePAM yes +<% if %w{squeeze}.include?(scope.lookupvar('::lsbdistcodename')) %> AuthorizedKeysFile /etc/ssh/userkeys/%u AuthorizedKeysFile2 /var/lib/misc/userkeys/%u +<% else %> +AuthorizedKeysFile /etc/ssh/userkeys/%u /var/lib/misc/userkeys/%u /etc/ssh/userkeys/%u.more +<% end %> PasswordAuthentication no