<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://thelinuxsource.org/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://thelinuxsource.org/index.php?action=history&amp;feed=atom&amp;title=Template%3ASSH-Policy</id>
		<title>Template:SSH-Policy - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://thelinuxsource.org/index.php?action=history&amp;feed=atom&amp;title=Template%3ASSH-Policy"/>
		<link rel="alternate" type="text/html" href="http://thelinuxsource.org/index.php?title=Template:SSH-Policy&amp;action=history"/>
		<updated>2026-04-16T01:42:05Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.23.15</generator>

	<entry>
		<id>http://thelinuxsource.org/index.php?title=Template:SSH-Policy&amp;diff=98&amp;oldid=prev</id>
		<title>Support at 02:01, 10 May 2017</title>
		<link rel="alternate" type="text/html" href="http://thelinuxsource.org/index.php?title=Template:SSH-Policy&amp;diff=98&amp;oldid=prev"/>
				<updated>2017-05-10T02:01:19Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 02:01, 10 May 2017&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 16:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 16:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* X11 over ssh is enabled, to allow various needed GUI utilities (and for Oracle installs).&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* X11 over ssh is enabled, to allow various needed GUI utilities (and for Oracle installs).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Note: Sometimes the &amp;quot;allowed unauthenticated connections&amp;quot; parameter (&amp;quot;MaxStartups&amp;quot;) is modified where needed to permit a larger number of rsync connections (primarily on DTS systems).&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Note: Sometimes the &amp;quot;allowed unauthenticated connections&amp;quot; parameter (&amp;quot;MaxStartups&amp;quot;) is modified where needed to permit a larger number of rsync connections (primarily on &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;data aggregation (backup/&lt;/ins&gt;DTS&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;/etc.) &lt;/ins&gt;systems).&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Support</name></author>	</entry>

	<entry>
		<id>http://thelinuxsource.org/index.php?title=Template:SSH-Policy&amp;diff=97&amp;oldid=prev</id>
		<title>Support: Created page with &quot;SSH Server configuration requirements (settings incorporated in company approved image from kickstart). * Ssh client configuration must not be modified, unless it is required...&quot;</title>
		<link rel="alternate" type="text/html" href="http://thelinuxsource.org/index.php?title=Template:SSH-Policy&amp;diff=97&amp;oldid=prev"/>
				<updated>2017-05-10T01:59:07Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;SSH Server configuration requirements (settings incorporated in company approved image from kickstart). * Ssh client configuration must not be modified, unless it is required...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;SSH Server configuration requirements (settings incorporated in company approved image from kickstart).&lt;br /&gt;
* Ssh client configuration must not be modified, unless it is required by a piece of software to function correctly (eg; oracle db software requires creating a local config file, specifically for the oracle user, for the software to function correctly in a multi-server RAC configuration).&lt;br /&gt;
* The standard ssh port must not be used (minimizes logging activity due to scanning/hacking attempts).&lt;br /&gt;
* Ssh protocol version 1, and related insecure protocol 1 settings must be disabled.&lt;br /&gt;
* Server keys must be increased to 1024 bits or higher (was 768).&lt;br /&gt;
* Direct root logins must be disabled (except from the console), configuration must be set to &amp;quot;PermitRootLogin no&amp;quot; except where locked-down root keys are utilized for a trusted host or an automated process, in which case the configuration must be set to &amp;quot;PermitRootLogin without-password&amp;quot;.&lt;br /&gt;
* Ssh strict modes checking (&amp;quot;StrictModes yes&amp;quot;) must be used, except on systems where a monitoring account or script processing account (like nrpe/applog) is accessing an application account (where an app home directory has g+r, which breaks strict mode).&lt;br /&gt;
* Authorized keys filename (&amp;quot;AuthorizedKeysFile .ssh/authorized_keys&amp;quot;) must be set/enforced, to disallow use of an authorized_keys2 file, in order to reduce ambiguity and prevent the use of multiple authorized key files.&lt;br /&gt;
* Insecure host-based authentication mechanisms must be disabled (&amp;quot;RhostsRSAAuthentication no&amp;quot;, &amp;quot;HostbasedAuthentication no&amp;quot;, &amp;quot;IgnoreUserKnownHosts yes&amp;quot;, &amp;quot;IgnoreRhosts yes&amp;quot;).&lt;br /&gt;
* Passwordless accounts must not be allowed (&amp;quot;PermitEmptyPasswords no&amp;quot;).&lt;br /&gt;
* GSS API authentication (&amp;quot;GSSAPIAuthentication no&amp;quot;) must be disabled, to prevent login delays &amp;amp; issues.&lt;br /&gt;
* TCP keep alive's (&amp;quot;TCPKeepAlive yes&amp;quot;) must be set, in order to avoid infinitely hanging sessions.&lt;br /&gt;
* Privilege separation must be enabled (&amp;quot;UsePrivilegeSeparation yes&amp;quot;).&lt;br /&gt;
* Ssh must be configured such that sessions will timeout after a period of inactivity (currently issues with this setup).&lt;br /&gt;
* Keys must be locked down in order to allow only the single host they are used/generated from, so that if the keys are used outside of that host, they will not work and are therefore useless (note: some keys are locked down to specific commands/directories and do not even allow shell access).&lt;br /&gt;
* X11 over ssh is enabled, to allow various needed GUI utilities (and for Oracle installs).&lt;br /&gt;
&lt;br /&gt;
Note: Sometimes the &amp;quot;allowed unauthenticated connections&amp;quot; parameter (&amp;quot;MaxStartups&amp;quot;) is modified where needed to permit a larger number of rsync connections (primarily on DTS systems).&lt;/div&gt;</summary>
		<author><name>Support</name></author>	</entry>

	</feed>