second commit
This commit is contained in:
32
ansible/roles/os_hardening/tasks/sshd.yml
Normal file
32
ansible/roles/os_hardening/tasks/sshd.yml
Normal file
@ -0,0 +1,32 @@
|
||||
---
|
||||
# SSH-Daemon des Jumphosts SELBST (administrativer Zugriff auf den Server) --
|
||||
# nicht zu verwechseln mit der SSH-Proxy-Funktion der Anwendung (app/ssh_proxy),
|
||||
# die eigene, unabhaengige Verbindungen zu den Zielsystemen aufbaut.
|
||||
# CIS 5.2.x.
|
||||
|
||||
- name: SSH-Daemon des Jumphosts haerten (vollstaendige Konfiguration inkl. Banner)
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/ssh/sshd_config.d/99-jumphost-hardening.conf
|
||||
owner: root
|
||||
group: root
|
||||
mode: "0644"
|
||||
content: |
|
||||
PermitRootLogin no
|
||||
PasswordAuthentication no
|
||||
KbdInteractiveAuthentication no
|
||||
PermitEmptyPasswords no
|
||||
X11Forwarding no
|
||||
AllowTcpForwarding no
|
||||
AllowAgentForwarding no
|
||||
PermitTunnel no
|
||||
MaxAuthTries 3
|
||||
MaxSessions 4
|
||||
LoginGraceTime 20
|
||||
ClientAliveInterval 300
|
||||
ClientAliveCountMax 2
|
||||
Banner /etc/issue.net
|
||||
LogLevel VERBOSE
|
||||
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com
|
||||
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,diffie-hellman-group16-sha512
|
||||
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com
|
||||
notify: restart sshd
|
||||
Reference in New Issue
Block a user