Re: modifications to sshd_config for security/hardening

2020-05-01 Thread Tim via users
On Fri, 2020-05-01 at 21:37 -0500, Chris Adams wrote: > FYI: "UseDNS no" has been the default in OpenSSH for a while now. Though, if you have a specific need, sometimes it is a good idea to specify them. Defaults can change. Or defaults applied by distribution-installed config files might not be

Re: modifications to sshd_config for security/hardening

2020-05-01 Thread Chris Adams
Once upon a time, Cameron Simpson said: > The UseDNS one is only slightly security - by disabling DNS lookup > of incoming clients we (a) speed things up, particularly on high > latency links and (b) stop leaking information about who is > connecting to use to upstream DNS servers (from the DNS qu

Re: modifications to sshd_config for security/hardening

2020-05-01 Thread Cameron Simpson
On 01May2020 11:18, bruce wrote: Looking through lots of online sites for making changes/mods to sshd_config files to harden/secure the process. Would it be cool to post the changes here for comment? Yes. Also, anyone have suggestions as well? My initial steps are always: - PermitRootLog

modifications to sshd_config for security/hardening

2020-05-01 Thread bruce
Hi. Looking through lots of online sites for making changes/mods to sshd_config files to harden/secure the process. Would it be cool to post the changes here for comment? Also, anyone have suggestions as well? thanks ___ users mailing list -- users@lis