Add 'ed25519-only' configuration

This commit is contained in:
Sven Velt 2021-10-19 09:39:44 +02:00
commit 9ff0979db4

24
vars/ssh_ed25519.yml Normal file
View file

@ -0,0 +1,24 @@
ssh_hardening_opts:
KexAlgorithms:
- curve25519-sha256
- curve25519-sha256@libssh.org
- sntrup761x25519-sha512@openssh.com
Ciphers:
- chacha20-poly1305@openssh.com
MACs:
- hmac-sha2-256-etm@openssh.com
- hmac-sha2-512-etm@openssh.com
- umac-128-etm@openssh.com
HostKeyAlgorithms:
- ssh-ed25519
- ssh-ed25519-cert-v01@openssh.com
- sk-ssh-ed25519@openssh.com
- sk-ssh-ed25519-cert-v01@openssh.com
PubkeyAcceptedAlgorithms:
- ssh-ed25519
- ssh-ed25519-cert-v01@openssh.com
GSSAPIKexAlgorithms:
- gss-curve25519-sha256-