mirror of
				https://github.com/jtesta/ssh-audit.git
				synced 2025-11-04 11:12:15 +01:00 
			
		
		
		
	Fixed optional host key values.
This commit is contained in:
		@@ -11,6 +11,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -11,6 +11,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -11,6 +11,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -11,6 +11,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -11,6 +11,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = sk-ssh-ed25519@openssh.com, ssh-ed25519-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -15,6 +15,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
 | 
					host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = sk-ssh-ed25519@openssh.com, ssh-ed25519-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -15,6 +15,9 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
# The host key types that must match exactly (order matters).
 | 
					# The host key types that must match exactly (order matters).
 | 
				
			||||||
host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
 | 
					host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
 | 
					optional host keys = sk-ssh-ed25519@openssh.com, ssh-ed25519-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -12,7 +12,7 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# Host key types that may optionally appear.
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
optional host keys = sk-ssh-ed25519@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com
 | 
					optional host keys = ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256@libssh.org, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256@libssh.org, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -12,7 +12,7 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
host keys = ssh-ed25519
 | 
					host keys = ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# Host key types that may optionally appear.
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
optional host keys = sk-ssh-ed25519@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com
 | 
					optional host keys = ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -16,7 +16,7 @@ dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
 | 
				
			|||||||
host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
 | 
					host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# Host key types that may optionally appear.
 | 
					# Host key types that may optionally appear.
 | 
				
			||||||
optional host keys = sk-ssh-ed25519@openssh.com,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com
 | 
					optional host keys = sk-ssh-ed25519@openssh.com, ssh-ed25519-cert-v01@openssh.com, sk-ssh-ed25519-cert-v01@openssh.com, rsa-sha2-256-cert-v01@openssh.com, rsa-sha2-512-cert-v01@openssh.com
 | 
				
			||||||
 | 
					
 | 
				
			||||||
# The key exchange algorithms that must match exactly (order matters).
 | 
					# The key exchange algorithms that must match exactly (order matters).
 | 
				
			||||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
					key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user