mirror of
https://github.com/jtesta/ssh-audit.git
synced 2024-11-22 02:21:40 +01:00
Added hardened OpenSSH policies.
This commit is contained in:
parent
2d4eb7da28
commit
cf815a6652
21
policies/openssh_7_7.txt
Normal file
21
policies/openssh_7_7.txt
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v7.7.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v7.7"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
21
policies/openssh_7_8.txt
Normal file
21
policies/openssh_7_8.txt
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v7.8.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v7.8"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
21
policies/openssh_7_9.txt
Normal file
21
policies/openssh_7_9.txt
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v7.9.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v7.9"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
21
policies/openssh_8_0.txt
Normal file
21
policies/openssh_8_0.txt
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v8.0.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v8.0"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
21
policies/openssh_8_1.txt
Normal file
21
policies/openssh_8_1.txt
Normal file
@ -0,0 +1,21 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v8.1.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v8.1"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
25
policies/openssh_8_2.txt
Normal file
25
policies/openssh_8_2.txt
Normal file
@ -0,0 +1,25 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v8.2.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v8.2"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# RSA host key sizes.
|
||||||
|
hostkey_size_rsa-sha2-256 = 4096
|
||||||
|
hostkey_size_rsa-sha2-512 = 4096
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
25
policies/openssh_8_3.txt
Normal file
25
policies/openssh_8_3.txt
Normal file
@ -0,0 +1,25 @@
|
|||||||
|
#
|
||||||
|
# Official policy for hardened OpenSSH v8.3.
|
||||||
|
#
|
||||||
|
|
||||||
|
name = "Hardened OpenSSH v8.3"
|
||||||
|
version = 1
|
||||||
|
|
||||||
|
# RSA host key sizes.
|
||||||
|
hostkey_size_rsa-sha2-256 = 4096
|
||||||
|
hostkey_size_rsa-sha2-512 = 4096
|
||||||
|
|
||||||
|
# Group exchange DH modulus sizes.
|
||||||
|
dh_modulus_size_diffie-hellman-group-exchange-sha256 = 2048
|
||||||
|
|
||||||
|
# The host key types that must match exactly (order matters).
|
||||||
|
host keys = rsa-sha2-512, rsa-sha2-256, ssh-ed25519
|
||||||
|
|
||||||
|
# The key exchange algorithms that must match exactly (order matters).
|
||||||
|
key exchanges = curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256
|
||||||
|
|
||||||
|
# The ciphers that must match exactly (order matters).
|
||||||
|
ciphers = chacha20-poly1305@openssh.com, aes256-gcm@openssh.com, aes128-gcm@openssh.com, aes256-ctr, aes192-ctr, aes128-ctr
|
||||||
|
|
||||||
|
# The MACs that must match exactly (order matters).
|
||||||
|
macs = hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com, umac-128-etm@openssh.com
|
Loading…
Reference in New Issue
Block a user