mirror of
https://github.com/jtesta/ssh-audit.git
synced 2025-09-05 05:58:22 +02:00
Added policy option to allow host key subsets and/or reorderings.
This commit is contained in:
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"errors": [],
|
||||
"host": "localhost",
|
||||
"passed": true,
|
||||
"policy": "Docker policy: test18 (version 1)",
|
||||
"port": 2222,
|
||||
"warnings": []
|
||||
}
|
@@ -0,0 +1,3 @@
|
||||
Host: localhost:2222
|
||||
Policy: Docker policy: test18 (version 1)
|
||||
Result: [0;32m✔ Passed[0m
|
17
test/docker/policies/policy_test18.txt
Normal file
17
test/docker/policies/policy_test18.txt
Normal file
@@ -0,0 +1,17 @@
|
||||
#
|
||||
# Docker policy: test18
|
||||
#
|
||||
|
||||
name = "Docker policy: test18"
|
||||
version = 1
|
||||
allow_algorithm_subset_and_reordering = false
|
||||
allow_hostkey_subset_and_reordering = true
|
||||
allow_larger_keys = false
|
||||
banner = "SSH-2.0-OpenSSH_8.0"
|
||||
compressions = none, zlib@openssh.com
|
||||
host keys = ssh-rsa, rsa-sha2-256, rsa-sha2-512, ecdsa-sha2-nistp256, ssh-ed25519, x
|
||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group-exchange-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group14-sha256, diffie-hellman-group14-sha1
|
||||
ciphers = chacha20-poly1305@openssh.com, aes128-ctr, aes192-ctr, aes256-ctr, aes128-gcm@openssh.com, aes256-gcm@openssh.com
|
||||
macs = umac-64-etm@openssh.com, umac-128-etm@openssh.com, hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, umac-64@openssh.com, umac-128@openssh.com, hmac-sha2-256, hmac-sha2-512, hmac-sha1
|
||||
host_key_sizes = {"ssh-rsa": {"hostkey_size": 3072}, "rsa-sha2-256": {"hostkey_size": 3072}, "rsa-sha2-512": {"hostkey_size": 3072}, "ssh-ed25519": {"hostkey_size": 256}}
|
||||
dh_modulus_sizes = {"diffie-hellman-group-exchange-sha256": 4096}
|
Reference in New Issue
Block a user