diff --git a/roles/0_basic_postinstall/files/hardened_sshd.conf b/roles/0_basic_postinstall/files/hardened_sshd.conf index b28a15a..21f4436 100644 --- a/roles/0_basic_postinstall/files/hardened_sshd.conf +++ b/roles/0_basic_postinstall/files/hardened_sshd.conf @@ -1,23 +1,29 @@ -# Disable root login entirely -PermitRootLogin no - +PubkeyAuthentication yes +AuthorizedKeysFile .ssh/authorized_keys +PasswordAuthentication no +KbdInteractiveAuthentication no +UsePAM no # Disable password authentication — keys only PasswordAuthentication no ChallengeResponseAuthentication no -UsePAM no + + +AllowGroups sshusers +PrintMotd no +AcceptEnv LANG LC_* +ClientAliveCountMax 0 +ClientAliveInterval 300 +Port 22 + + +# Disable root login entirely +PermitRootLogin no # Limit authentication attempts MaxAuthTries 3 -MaxSessions 2 - -# Allow only your specific user -AllowUsers deploy +MaxSessions 3 # Use modern key exchange and ciphers, prioritize post-quantum algorithms (mlkem and sntrup) KexAlgorithms mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com -MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com - -# Connection timeout -ClientAliveInterval 300 -ClientAliveCountMax 2 \ No newline at end of file +MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com \ No newline at end of file