mirror of
https://github.com/jtesta/ssh-audit.git
synced 2024-12-22 22:15:22 +01:00
Added Ubuntu client policies.
This commit is contained in:
parent
8fb07edafd
commit
00ce44e728
19
policies/ubuntu_client_16_04.txt
Normal file
19
policies/ubuntu_client_16_04.txt
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH on Ubuntu 16.04 LTS.
|
||||||
|
#
|
||||||
|
|
||||||
|
client policy = true
|
||||||
|
name = "Ubuntu Client 16.04 LTS"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519, ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256, rsa-sha2-512, ssh-rsa-cert-v01@openssh.com
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256@libssh.org, diffie-hellman-group-exchange-sha256, ext-info-c
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
19
policies/ubuntu_client_18_04.txt
Normal file
19
policies/ubuntu_client_18_04.txt
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH on Ubuntu 18.04 LTS.
|
||||||
|
#
|
||||||
|
|
||||||
|
client policy = true
|
||||||
|
name = "Ubuntu Client 18.04 LTS"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519, ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256, rsa-sha2-512, ssh-rsa-cert-v01@openssh.com
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256, ext-info-c
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
19
policies/ubuntu_client_20_04.txt
Normal file
19
policies/ubuntu_client_20_04.txt
Normal file
@ -0,0 +1,19 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH on Ubuntu 20.04 LTS.
|
||||||
|
#
|
||||||
|
|
||||||
|
client policy = true
|
||||||
|
name = "Ubuntu Client 20.04 LTS"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519, ssh-ed25519-cert-v01@openssh.com, sk-ssh-ed25519@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512, rsa-sha2-512-cert-v01@openssh.com, ssh-rsa-cert-v01@openssh.com
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256, ext-info-c
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
Loading…
Reference in New Issue
Block a user