Skip to content

HBSD: harden openssh-server by the recommendations of Lynis

Loic requested to merge loic/HardenedBSD:harden_openssh into hardened/current/master
  • Consider hardening SSH configuration [SSH-7408]
Details  : AllowTcpForwarding (set YES to NO)
  • Consider hardening SSH configuration [SSH-7408]
Details  : ClientAliveCountMax (set 3 to 2)
  • Consider hardening SSH configuration [SSH-7408]
Details  : Compression (set YES to NO)
  • Consider hardening SSH configuration [SSH-7408]
Details  : LogLevel (set INFO to VERBOSE)
  • Consider hardening SSH configuration [SSH-7408]
Details  : MaxAuthTries (set 6 to 3)
  • Consider hardening SSH configuration [SSH-7408]
Details  : TCPKeepAlive (set YES to NO)
  • Consider hardening SSH configuration [SSH-7408]
Details  : UseDNS (set YES to NO)
  • Consider hardening SSH configuration [SSH-7408]
Details  : X11Forwarding (set YES to NO)
  • Consider hardening SSH configuration [SSH-7408]
Details  : AllowAgentForwarding (set YES to NO)

Signed-off-by: Loic loic.f@hardenedbsd.org

Edited by Loic

Merge request reports