mirror of
https://github.com/mail-in-a-box/mailinabox.git
synced 2025-04-21 03:02:09 +00:00
per Yodax suggestion used built in python tool I was unaware existed.
This commit is contained in:
parent
bf8e095b36
commit
7c526313fd
@ -220,9 +220,12 @@ APT::Periodic::Verbose "1";
|
||||
EOF
|
||||
|
||||
# Harden SSH and disable weak ciphers
|
||||
grep -q -F "Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128 \
|
||||
MACs hmac-sha1,umac-64@openssh.com,hmac-ripemd160" /etc/ssh/sshd_config || echo "Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128 \
|
||||
MACs hmac-sha1,umac-64@openssh.com,hmac-ripemd160" >> /etc/ssh/ssh_config
|
||||
echo "disabling weak SSH ciphers"
|
||||
tools/editconf.py /etc/ssh/sshd_config -s \
|
||||
Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128 \
|
||||
MACs hmac-sha1,umac-64@openssh.com,hmac-ripemd160
|
||||
|
||||
restart_service ssh
|
||||
|
||||
# ### Firewall
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user