Vault - sshd_config (SSH server)
Vault Solution · Config document · referenced from Linux hardening
The SSH server configuration of every load-balancer and Vault node as built in 2023, for the OpenSSH 8.0 of Oracle Linux 8. It is kept as the record of what ran. For a new build start from the maintained profile: OpenSSH - Hardened SSHD configuration.
| Item | Value |
|---|---|
| Path on the host | /etc/ssh/sshd_config |
| Shown here | load-balancer and Vault nodes |
| Deployed on | every server, with the bastion differences listed below |
| Checked with | sshd -t |
| Applied with | systemctl reload sshd |
The file
#------------------------------------------------------------------------------ # File: sshd_config # Description: Hardened SSHD configuration # Author: admin01 # Date: 2023 # # REF-1: https://infosec.mozilla.org/guidelines/openssh # REF-2: https://www.ssi.gouv.fr/en/guide/openssh-secure-use-recommendations/ # REF-3: https://github.com/decalage2/awesome-security-hardening#ssh # REF-4: https://bettercrypto.org/#ssh # REF-5: https://linux-audit.com/audit-and-harden-your-ssh-configuration/ # REF-6: https://www.putorius.net/how-to-secure-ssh-daemon.html # REF-7: https://www.cyberciti.biz/tips/linux-unix-bsd-openssh-server-best-practices.html #------------------------------------------------------------------------------ #------------------------------------------------------------------------------ # Basic configuration #------------------------------------------------------------------------------ # StricModes specifies whether sshd should check file modes and ownership of the # user's files and home directory before accepting login. This is normally # desirable because novices sometimes accidentally leave their directory or files # world-writable. StrictModes yes # SSH protocol version (Protocol 1 is fundamentally broken) Protocol 2 # Hostkey specifies a file containing a private host key used by SSH # Allowing only ECDSA pubic key authentication HostKey /etc/ssh/ssh_host_ed25519_key # Allowing only internal SFTP. # Log sftp level file access (read/write/etc.) that would not be easily logged otherwise. Subsystem sftp internal-sftp # Accept locale-related environment variables AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE AcceptEnv XMODIFIERS # Specifies whether ~/.ssh/environment and environment= options in # ~/.ssh/authorized_keys are processed by sshd. PermitUserEnvironment no # Specifies whether sshd should look up the remote host name, and to check that # the resolved host name for the remote IP address maps back to the very same # IP address. UseDNS no # Disabling the compression. Compression can cause security issues. # If compression is allowed in an SSH connection prior to authentication, # vulnerabilities in the compression software could result in compromise of # the system from an unauthenticated connection, potentially with root privileges. Compression no #------------------------------------------------------------------------------ # Network binding #------------------------------------------------------------------------------ # Port specifies the port number that sshd listens on Port 22 # Specifies the local address/es sshd should listen on ListenAddress <NODE_IP> # Listen only on IPv4 AddressFamily inet #------------------------------------------------------------------------------ # Banner & MOTD #------------------------------------------------------------------------------ # The contents of the specified file are sent to the remote user before # authentication is allowed. Banner /etc/issue.net # It is recommended to use pam_motd in /etc/pam.d/sshd instead of PrintMotd, # as it is more configurable and versatile than the built-in version. PrintMotd no #------------------------------------------------------------------------------ # Cryptography #------------------------------------------------------------------------------ # Allowed ciphers Ciphers chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com # Allowed host key algorithms HostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,ecdsa-sha2-nistp521-cert-v01@openssh.com # Allowed Key Exchange (KEX) algorithms KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256 # Allowed Message Authentication Codes (MACs) MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-512,hmac-sha2-256-etm@openssh.com,hmac-sha2-256 #------------------------------------------------------------------------------ # Logging #------------------------------------------------------------------------------ # Facility code that is used when logging messages from sshd. SyslogFacility AUTHPRIV # Verbosity level that is used when logging messages from sshd. # LogLevel VERBOSE logs user's key fingerprint on login. Needed to have a clear # audit track of which key was using to log in. LogLevel INFO #------------------------------------------------------------------------------ # Connection #------------------------------------------------------------------------------ # Sets a timeout interval in seconds after which if no data has been received # from the client, sshd(8) will send a message through the encrypted channel to # request a response from the client. ClientAliveInterval 900 # Sets the number of client alive messages which may be sent without sshd # receiving any messages back from the client. If this threshold is reached # while client alive messages are being sent, sshd will disconnect the client, # terminating the session. ClientAliveCountMax 0 # Specifies the maximum number of concurrent unauthenticated connections to the # SSH daemon. Additional connections will be dropped until authentication # succeeds or the LoginGraceTime expires for a connection. MaxStartups 10:30:60 # Specifies whether the system should send TCP keepalive messages to the other side. TCPKeepAlive no #------------------------------------------------------------------------------ # Authentication #------------------------------------------------------------------------------ # The server disconnects after this time if the user has not successfully logged in. LoginGraceTime 60 # Disable SSH login for the "root". PermitRootLogin no # Specifies the maximum number of authentication attempts permitted per connection. MaxAuthTries 4 # Specifies the maximum number of open sessions permitted per network connection. MaxSessions 10 # Allowing only public key authentication. AuthenticationMethods publickey # Enabling public key authentication. PubkeyAuthentication yes # The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2 # but this is overridden so installations will only check .ssh/authorized_keys AuthorizedKeysFile .ssh/authorized_keys # Disabling host-based authentication HostbasedAuthentication no # Don't read the user's ~/.rhosts and ~/.shosts files IgnoreRhosts yes # Disabling the empty passwords. PermitEmptyPasswords no # Disabling password authentication. PasswordAuthentication no # Specifies whether challenge-response authentication is allowed (e.g. via PAM or # though authentication styles supported in login.conf. ChallengeResponseAuthentication no # Specifies whether to allow keyboard-interactive authentication. KbdInteractiveAuthentication no # Set this to 'yes' to enable PAM authentication, account processing, # and session processing. If this is enabled, PAM authentication will # be allowed through the ChallengeResponseAuthentication and # PasswordAuthentication. Depending on your PAM configuration, # PAM authentication via ChallengeResponseAuthentication may bypass # the setting of "PermitRootLogin without-password". # If you just want the PAM account and session checks to run without # PAM authentication, then enable this but set PasswordAuthentication # and ChallengeResponseAuthentication to 'no'. # WARNING: 'UsePAM no' is not supported in Fedora and may cause several # problems. UsePAM yes #------------------------------------------------------------------------------ # Forwarding #------------------------------------------------------------------------------ # Disabling ssh-agent forwarding. AllowAgentForwarding no # Disabling TCP forwarding. AllowTcpForwarding no # Disabling StreamLocal (Unix socket) forwarding. AllowStreamLocalForwarding no # Disable all forwardings. DisableForwarding yes # Specifies whether remote hosts are allowed to connect to ports forwarded for the client. # Forwarded ports are forced to bind to 127.0.0.1 instad of 0.0.0.0. GatewayPorts no # Specifies whether tun device forwarding is allowed. PermitTunnel no # Disabling X11 forwarding. X11Forwarding no #------------------------------------------------------------------------------ # Users & groups #------------------------------------------------------------------------------ # Only the allowed users can connect. AllowUsers admin01 admin02 admin03 # Only the allowed groups can connect. AllowGroups wheel
What changes on the bastion host
| Directive | All servers | Bastion |
|---|---|---|
AllowAgentForwarding | no | yes |
AllowTcpForwarding | no | yes |
DisableForwarding | yes | no |
Reading it today
ClientAliveCountMax 0terminated an idle session afterClientAliveIntervalon OpenSSH 8.0. Since OpenSSH 8.2 the value 0 disables termination altogether, so on a newer release this line does the opposite of what it did here.Protocol 2has been ignored since OpenSSH 7.4, andChallengeResponseAuthenticationis a deprecated alias ofKbdInteractiveAuthentication.- The static
Ciphers,KexAlgorithms,MACsandHostKeyAlgorithmslists froze the 2023 state. They exclude the post-quantum key exchange that current OpenSSH negotiates by default; the maintained profile leaves negotiation to the installed version for that reason. AllowUserstogether withAllowGroupsmeans a login must satisfy both. That was intended: a named administrator who is also inwheel.