mirror of
				https://github.com/jtesta/ssh-audit.git
				synced 2025-11-04 03:02:15 +01:00 
			
		
		
		
	Added policy option to allow host key subsets and/or reorderings.
This commit is contained in:
		
							
								
								
									
										17
									
								
								test/docker/policies/policy_test18.txt
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										17
									
								
								test/docker/policies/policy_test18.txt
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,17 @@
 | 
			
		||||
#
 | 
			
		||||
# Docker policy: test18
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
name = "Docker policy: test18"
 | 
			
		||||
version = 1
 | 
			
		||||
allow_algorithm_subset_and_reordering = false
 | 
			
		||||
allow_hostkey_subset_and_reordering = true
 | 
			
		||||
allow_larger_keys = false
 | 
			
		||||
banner = "SSH-2.0-OpenSSH_8.0"
 | 
			
		||||
compressions = none, zlib@openssh.com
 | 
			
		||||
host keys = ssh-rsa, rsa-sha2-256, rsa-sha2-512, ecdsa-sha2-nistp256, ssh-ed25519, x
 | 
			
		||||
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, diffie-hellman-group-exchange-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group14-sha256, diffie-hellman-group14-sha1
 | 
			
		||||
ciphers = chacha20-poly1305@openssh.com, aes128-ctr, aes192-ctr, aes256-ctr, aes128-gcm@openssh.com, aes256-gcm@openssh.com
 | 
			
		||||
macs = umac-64-etm@openssh.com, umac-128-etm@openssh.com, hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, hmac-sha1-etm@openssh.com, umac-64@openssh.com, umac-128@openssh.com, hmac-sha2-256, hmac-sha2-512, hmac-sha1
 | 
			
		||||
host_key_sizes = {"ssh-rsa": {"hostkey_size": 3072}, "rsa-sha2-256": {"hostkey_size": 3072}, "rsa-sha2-512": {"hostkey_size": 3072}, "ssh-ed25519": {"hostkey_size": 256}}
 | 
			
		||||
dh_modulus_sizes = {"diffie-hellman-group-exchange-sha256": 4096}
 | 
			
		||||
		Reference in New Issue
	
	Block a user