-
Notifications
You must be signed in to change notification settings - Fork 13
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Improved sshd_config template #560
Improved sshd_config template #560
Conversation
… depending on inventory group to prevent issues with MaxStartups especially on jumphosts.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
See inline comments
roles/sshd/defaults/main.yml
Outdated
@@ -1,4 +1,43 @@ | |||
--- | |||
sshd_moduli_minimum: 3072 | |||
data_transfer_only_group: sftp-only | |||
# | |||
# Reduce LoginGraceTime on machines with direct internet connection to increase security | |||
# and reduce the number of opened but not yet authenticated connections consumeing resources. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
typo: consuming
roles/sshd/defaults/main.yml
Outdated
# The probability increases linearly and all connection attempts are refused | ||
# if the number of unauthenticated connections reaches "full" (100). | ||
# See also https://bugs.launchpad.net/openstack-ansible/+bug/1479812 | ||
# A connection is is no longer in unauthenticated state untill |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Twice the word "is"
Tweaked
LoginGraceTime
andMaxSessions
depending on inventory group to prevent issues withMaxStartups
especially on jumphosts.