From 08c301ebf380dfe292cca86355c6110bd999940a Mon Sep 17 00:00:00 2001 From: Paul McGoldrick Date: Thu, 28 Sep 2017 10:03:44 -0700 Subject: initial seed code commit VVP-6 Change-Id: I62f1f86c7a187585e98ccf52b68f57c8d9073175 Signed-off-by: Paul McGoldrick --- assets/sshd_config | 57 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 57 insertions(+) create mode 100755 assets/sshd_config (limited to 'assets/sshd_config') diff --git a/assets/sshd_config b/assets/sshd_config new file mode 100755 index 0000000..e2e7708 --- /dev/null +++ b/assets/sshd_config @@ -0,0 +1,57 @@ +# ============LICENSE_START======================================================= +# org.onap.vvp/gitlab +# =================================================================== +# Copyright © 2017 AT&T Intellectual Property. All rights reserved. +# =================================================================== +# +# Unless otherwise specified, all software contained herein is licensed +# under the Apache License, Version 2.0 (the “License”); +# you may not use this software except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# +# +# Unless otherwise specified, all documentation contained herein is licensed +# under the Creative Commons License, Attribution 4.0 Intl. (the “License”); +# you may not use this documentation except in compliance with the License. +# You may obtain a copy of the License at +# +# https://creativecommons.org/licenses/by/4.0/ +# +# Unless required by applicable law or agreed to in writing, documentation +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# ============LICENSE_END============================================ +# +# ECOMP is a trademark and service mark of AT&T Intellectual Property. +Port 22 +ChallengeResponseAuthentication no +HostKey /etc/gitlab/ssh_host_rsa_key +HostKey /etc/gitlab/ssh_host_ecdsa_key +HostKey /etc/gitlab/ssh_host_ed25519_key +Protocol 2 +PermitRootLogin no +PasswordAuthentication no +MaxStartups 100:30:200 +AllowUsers git +PrintMotd no +PrintLastLog no +PubkeyAuthentication yes + +# Fix: User username not allowed because account is locked +# With "UsePAM yes" the "!" is seen as a password disabled account and not fully locked so ssh public key login works +UsePAM yes + +# Disabling use DNS in ssh since it tends to slow connecting +UseDNS no -- cgit 1.2.3-korg